Back to Search Start Over

SMRL: A Metamorphic Security Testing Tool for Web Systems

Authors :
Mai, Xuan Phu
Göknil, Arda
Pastore, Fabrizio
Briand, Lionel
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Software Verification and Validation Lab (SVV Lab) [research center]
Source :
info:eu-repo/grantAgreement/EC/H2020/694277
Publication Year :
2020

Abstract

We present a metamorphic testing tool that alleviates the oracle problem in security testing. The tool enables engineers to specify metamorphic relations that capture security properties of Web systems. It automatically tests Web systems to detect vulnerabilities based on those relations. We provide a domain-specific language accompanied by an Eclipse editor to facilitate the specification of metamorphic relations. The tool automatically collects the input data and transforms the metamorphic relations into executable Java code in order to automatically perform security testing based on the collected data. The tool has been successfully evaluated on a commercial system and a leading open source system (Jenkins). Demo video: https://youtu.be/9kx6u9LsGxs.

Details

Language :
English
Database :
OpenAIRE
Journal :
info:eu-repo/grantAgreement/EC/H2020/694277
Accession number :
edsair.od......2658..0ec37994ff557a0c179deb74e487e9cb