Domestic and foreign experience in security testing

DOI: 10.21293/1818-0442-2024-27-1-37-43

Download article in PDF format

JATS xml

Abstract: Testing is considered as a separate and independent life cycle stage of any secure software development. However, the testing is present at another stages, such as development stage or the technical support stage after software release. This paper describes the domestic and foreign experience in security testing which is considered both at specific life cycle stage of secure software development and as a whole. Each method has its own benefits and drawbacks. The experience of researchers will be useful in own methodology for software security testing.

Keywords: developing secure software, security measures, security testing methods

For citation:
Derkach E. A., Shelupanov A. A. Domestic and foreign experience in security testing. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2024, vol. 27, no. 1, pp. 37–43. DOI: 10.21293/1818-0442-2024-27-1-37-43

Authors and copyright holders:

  • Derkach E. A. , Tomsk State University of Control Systems and Radioelectronics (Tomsk, Russia)
  • Shelupanov A. A. , Tomsk State University of Control Systems and Radioelectronics (Tomsk, Russia)

  • 1. Babarinov A.V., Dorofeev A.V., Markov A.S., Tzirlov V.L. Sem' bezopasnyh informacionnyh tekhnologij [Seven secure information technologies]. Moscow, DMK Press, 2017, 224 p. (in Russ.).
  • 2. Daud M.I. Secure Software Development Model: A Guide for Secure Software Life Cycle. Proceedings of the International MultiConference of Engineers and Computer Scientists, 2010, vol. 1, pр. 1–5.
  • 3. Trautsch F., Herbold S., Grabowski J. Are unit and integration test definitions still valid for modern Java projects? An empirical study on open-source projects Journal of Systems and Software, 2020, vol. 159, pр. 1–15.
  • 4. Kshirasagar N., Priyadarshi T. Software testing and quality assurance. Theory and practice. A John Wiley & Sons, Inc. Publication, 2008, 616 p. (in Eng.).
  • 5. Herbold S., Haar T. Smoke testing for machine learning: simple tests to discover severe bugs Empirical Software Engineering, 2022, vol. 27, pр. 1–30.
  • 6. Markov A.S., Tzirlov V.L., Oleksenko I.A., Maslov V.G. Testirovanie i ispytaniya programmnogo obespecheniya po trebovaniyam bezopasnosti informacii [Software testing according to information security requirements] Izvestiya Instituta inzhenernoy phiziki, 2009, no. 2, pр. 2–6 (in Russ.).
  • 7. Mukminov V.A., Voinov Y.V., Balandin A.V. O novyh metodah i algoritmah testirovaniya programmnogo obespecheniya [About new methods and algorithms for software testing] Dvoinye Tekhnologii, 2011, no. 2, pр. 22–25 (in Russ.).
  • 8. Lyapustin A.E., Lyapustin M.E. Sposoby ispytaniya sredstv zashchity informacii [Methods for testing information security tools] Evrazijskij nauchnyj zhurnal, 2015, no. 6, pр. 193–196 (in Russ.).
  • 9. Borisova T.M., Kuznetsov A.V., Oblomova A.I. Testirovanie sredstv zashchity informacii [Testing information security tools] Informacionnoe protivodejstvie ugrozam terrorizma, 2013, no. 21, pр. 59–67 (in Russ.).
  • 10. Bugaeva A.A., Denisenko V.V. Process testirovaniya, metody i tipy testirovaniya programmnogo obespecheniya [Testing process, methods and types of software testing] Sinergiya Nauk, 2022, no. 72, pр. 92–102 (in Russ.).
  • 11. Bederdinova O.I., Ivanova L.A. Sovershenstvovanie metoda testirovaniya programmnogo obespecheniya «Belyj yashchik» [Improving the White Box Software Testing Method] Vestnik Severnogo (Arkticheskogo) federalnogo universiteta, 2014. no. 2, pр. 113–123 (in Russ.).
  • 12. Zielinski M., Groenboom R. Using Advanced Code Analysis for Boosting Unit Test Creation IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW), 2021, vol. 1, pр. 1–5.
  • 13. Mishra D.B., Mishra R., Das K.N., Acharya A.A. Test Case Generation and Optimization for Critical Path Testing Using Genetic Algorithm Soft Computing for Problem Solving, 2022, vol. 1, pр. 67–80.
  • 14. Casola V., Benedictis A., Mazzocca C., Orbinato V. Secure software development and testing: A model-based methodology, Computers & Security, 2024, vol. 137, p. 1–16.
  • 15. Luo D., Li T., Chen L., Zou H., Shi M. Grammar-based fuzz testing for microprocessor RTL design Integration, 2022, pр. 64–73.
  • 16. Park L.H., Kim J., Park J., Kwon T. Mixed and constrained input mutation for effective fuzzing of deep learning systems Information Sciences, 2022, vol. 614, pр. 497–517.
  • 17. Zhao X., Qu H., Xu J., Li Sh., Wang G.-G. AMSFuzz: An adaptive mutation schedule for fuzzing Expert Systems with Applications, 2022, vol. 208, р. 118162.
  • 18. Tao Ch., Tao Y., Guo H., Huang Zh., Sun X. DLRegion: Coverage-guided fuzz testing of deep neural networks with region-based neuron selection strategies // Information and Software Technology, 2023, vol. 162, р. 107266.
  • 19. Chen Ch., Cui B., Ma J., Wu R., Guo J. A systematic review of fuzzing techniques, Computers & Security, 2018, vol. 75, pр. 118–137.
  • 20. Godefroid P. Fuzzing: Hack, Art and Science Communications of the ACM, 2020, vol. 63, pр. 70–76.
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates