Projekt per år
Sammanfattning
Security verification of software systems is vital to ensure they are resilient against targeted attacks. Any vulnerability in the software should be discovered, classified, and resolved promptly to ensure the system’s operational correctness and functional safety. However, testing and program debugging of complex industrial control systems are often challenging due to the test oracle problem. In this work, we discuss an integrated method for test generation and fault localization using metamorphic testing. Our method extracts metamorphic relation from the system specification and uses it as the derived test oracle to distinguish the successful and failed tests for spectrum-based fault localization. The proposed approach consists of two phases: a test generation phase using metamorphic testing and a fault localization phase to assist with the root cause analysis and failure diagnosis. The method is exemplified on a load position system without explicit specifications of the test oracle, and the results show that it is effective in discovering vulnerabilities in the application and significantly assists the developers with root cause analysis of identified faults that reduces the overall failure diagnosis effort.
Originalspråk | Engelska |
---|---|
Titel på värdpublikation | CyberSecurity in a DevOps Environment |
Undertitel på värdpublikation | From Requirements to Monitoring |
Redaktörer | Andrey Sadovykh, Dragos Truscan, Wissam Mallouli, Ana Rosa Cavalli, Cristina Seceleanu, Alessandra Bagnato |
Förlag | Springer |
Kapitel | 5 |
Sidor | 127-159 |
ISBN (elektroniskt) | 978-3-031-42212-6 |
ISBN (tryckt) | 978-3-031-42211-9 |
DOI | |
Status | Publicerad - 2023 |
MoE-publikationstyp | A3 Del av bok eller annan forskningsbok |
Fingeravtryck
Fördjupa i forskningsämnen för ”Metamorphic Testing for Verification and Fault Localization in Industrial Control Systems”. Tillsammans bildar de ett unikt fingeravtryck.Projekt
- 1 Slutfört
-
VeriDevOps: Automated Protection and Prevention to Meet Security Requirements in DevOps Environments
Truscan, D., Porres Paltor, I., Ashraf, A., Ahmad, T., Chariyarupadannayil Sudheerbabu, G. & Chapagain, S.
01/10/20 → 31/01/24
Projekt: EU