Back to Search Start Over

A systematic classification of security regression testing approaches.

Authors :
Felderer, Michael
Fourneret, Elizabeta
Source :
International Journal on Software Tools for Technology Transfer; Jun2015, Vol. 17 Issue 3, p305-319, 15p
Publication Year :
2015

Abstract

The openness of modern IT systems and their permanent change make it challenging to keep these systems secure. A combination of regression and security testing called security regression testing, which ensures that changes made to a system do not harm its security, are therefore of high significance and the interest in such approaches has steadily increased. In this article we present a systematic classification of available security regression testing approaches based on a solid study of background and related work to sketch which parts of the research area seem to be well understood and evaluated, and which ones require further research. For this purpose we extract approaches relevant to security regression testing from computer science digital libraries based on a rigorous search and selection strategy. Then, we provide a classification of these according to security regression approach criteria: abstraction level, security issue, regression testing techniques, and tool support, as well as evaluation criteria, for instance evaluated system, maturity of the system, and evaluation measures. From the resulting classification we derive observations with regard to the abstraction level, regression testing techniques, tool support as well as evaluation, and finally identify several potential directions of future research. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
14332779
Volume :
17
Issue :
3
Database :
Complementary Index
Journal :
International Journal on Software Tools for Technology Transfer
Publication Type :
Academic Journal
Accession number :
102643829
Full Text :
https://doi.org/10.1007/s10009-015-0365-2