Model Inference and Security Testing in the SPaCIoS Project - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2014

Model Inference and Security Testing in the SPaCIoS Project

Résumé

The SPaCIoS project has as goal the validation and testing of security properties of services and web applications. It proposes a methodology and tool collection centered around models described in a dedicated specification language, supporting model inference, mutation-based testing, and model checking. The project has developed two approaches to reverse engineer models from implementations. One is based on remote interaction (typically through an HTTP connection) to observe the runtime behaviour and infer a model in black-box mode. The other is based on analysis of application code when available. This paper presents the reverse engineering parts of the project, along with an illustration of how vulnerabilities can be found with various SPaCIoS tool components on a typical security benchmark.

Domaines

Informatique
Fichier non déposé

Dates et versions

hal-00976110 , version 1 (09-04-2014)

Identifiants

  • HAL Id : hal-00976110 , version 1

Citer

Matthias Buchler, Karim Hossen, Petru Florin Mihancea, Marius Minea, Roland Groz, et al.. Model Inference and Security Testing in the SPaCIoS Project. IEEE Working Conference on Reverse Engineering, CSMR-WCRE 2014, 2014, Antwerp, Belgium. pp.411-414. ⟨hal-00976110⟩
298 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More