Assessing the Usefulness of Testing for Validating the Correctness of Security Risk Models Based on an Industrial Case Study
Research report
View/ Open
Date
2014Metadata
Show full item recordCollections
- Publikasjoner fra CRIStin - SINTEF AS [6009]
- SINTEF Digital [2568]
Abstract
We present the results of an evaluation in which the objective was to assess how useful testing is for validating and gaining confidence in the correctness of security risk models. The evaluation is based on a case study where the target system analyzed was a web-based application. The evaluation suggests that the testing was useful in the sense that it yielded new information which resulted in an update of the security risk model after testing. Oppdragsgiver: Norwegian Research Council