Integration of Formal Methods and Testing for Model-Based Security Engineering

By Achim D. Brucker.

We present a brief overview of various security testing works that range from applying off-the-shell tools (both dynamic tools as well as static program analysis) to theorem-prover based testing for ensuring the compliance of systems to high-level security policies.

Moreover, we report on the process of selecting the most appropriate (security) testing tools during product development derive open research questions based on our experience in developing, introducing, and applying (security) testing tools at SAP SE.

Please cite this work as follows:
A. D. Brucker, “Integration of formal methods and testing for model-based security engineering,” presented at the NII shonan meeting seminar 048 “integration of formal method and testing for model-based systems engineering,” Shonan, Japan, Dec. 01, 2014. Author copy: https://logicalhacking.com/publications/talk-brucker-mbst-2014/

BibTeX
@Unpublished{ talk:brucker:mbst:2014,
  date       = {2014-12-01},
  title      = {Integration of Formal Methods and Testing for Model-Based
                Security Engineering},
  author     = {Achim D. Brucker},
  venue      = {Shonan, Japan},
  year       = {2014},
  eventtitle = {NII Shonan Meeting Seminar 048 ``Integration of Formal Method
                and Testing for Model-Based Systems Engineering''},
  abstract   = {We present a brief overview of various security testing works
                that range from applying off-the-shell tools (both dynamic
                tools as well as static program analysis) to theorem-prover
                based testing for ensuring the compliance of systems to
                high-level security policies.
                
                Moreover, we report on the process of selecting the most
                appropriate (security) testing tools during product
                development derive open research questions based on our
                experience in developing, introducing, and applying (security)
                testing tools at SAP SE.},
  areas      = {software, formal methods},
  note       = {Author copy: \url{https://logicalhacking.com/publications/talk-brucker-mbst-2014/}},
  pdf        = {https://logicalhacking.com/publications/talk-brucker-mbst-2014/talk-brucker-mbst-2014.pdf},
}