2011Unpublished venueRequires access

Mutation Analysis of Magento for Evaluating Threat Model-Based Security Testing

Lijo Thomas, Weifeng Xu, Dianxiang Xu

Open publisher page 5 citations

Abstract

Security testing is a major means for assuring software security and many security testing techniques have been developed in the past. Benchmarks, however, are in great demands for empirically evaluating the vulnerability detection capabilities of these techniques. To develop such a benchmark, this paper presents an approach to security mutation analysis of Magento, a fully-fledged open source e-commerce web application for evaluating automated security testing techniques. We create security mutants by injecting vulnerabilities in a systematic way. Specifically, we consider the causes of vulnerabilities according to OWASP's top 10 web application security risks, the application's business logic, as well as various consequences of vulnerabilities (i.e., STRIDE attacks). We have created 63 mutants and applied them successfully to the evaluation of two security testing techniques that use threat trees and threat nets as threat models for test generation. Our experiments show that these testing methods can kill most of the mutants but cannot detect the vulnerabilities that are not captured by the threat models.

About this research paper

What this paper is about

Security testing is a major means for assuring software security and many security testing techniques have been developed in the past. Benchmarks, however, are in great demands for empirically evaluating the vulnerability detection capabilities of these techniques. To develop such a benchmark, this paper presents an approach to security mutation analysis of Magento, a fully-fledged open source e-commerce web application for evaluating automated security testing techniques. We create security mutants by injecting vulnerabilities in a systematic way. Specifically, we consider the causes of vulnerabilities according to OWASP's top 10 web application security risks, the application's business logic, as well as various consequences of vulnerabilities (i.e., STRIDE attacks). We have created 63 mutants and applied them successfully to the evaluation of two security testing techniques that use threat trees and threat nets as threat models for test generation. Our experiments show that these testing methods can kill most of the mutants but cannot detect the vulnerabilities that are not captured by the threat models.

Why it matters

OpenAlex reports 5 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Security testing is a major means for assuring software security and many security testing techniques have been developed in the past. Benchmarks, however, are in great demands for empirically evaluating the vulnerability detection capabilities of these techniques. To develop such a benchmark, this paper presents an approach to security mutation analysis of Magento, a fully-fledged open source e-commerce web application for evaluating automated security testing techniques. We create security mutants by injecting vulnerabilities in a systematic way. Specifically, we consider the causes of vulnerabilities according to OWASP's top 10 web application security risks, the application's business logic, as well as various consequences of vulnerabilities (i.e., STRIDE attacks). We have created 63 mutants and applied them successfully to the evaluation of two security testing techniques that use threat trees and threat nets as threat models for test generation. Our experiments show that these testing methods can kill most of the mutants but cannot detect the vulnerabilities that are not captured by the threat models.

Key concepts: Security testing, Computer science, Threat model, Software security assurance, Computer security, Security through obscurity, Vulnerability (computing), Application security

Related papers

Back to paper searchBrowse research topicsOriginal source
Mutation Analysis of Magento for Evaluating Threat Model-Based Security Testing — Research Paper | ScholarLens