Title
An Alternative Threat Model-based Approach for Security Testing
Abstract
AbstractIn modern interaction, web applications has gained more and more popularity, which leads to a significate growth of exposure to malicious users and vulnerability attacks. This causes organizations and companies to lose valuable information and suffer from bad reputation. One of the effective mitigation practices is to perform security testing against the application before release it to the market. This solution won't protect web application 100% but it will test the application against malicious codes and reduce the high number of potential attacks on web application. One of known security testing approach is threat modeling, which provides an efficient technique to identify threats that can compromise system security. The authors proposed method, in this paper, focuses on improving the effectiveness of the categorization of threats by using Open 10 Web Application Security Project's OWASP that are the most critical web application security risks in generating threat trees in order to cover widely known security attacks.
Year
DOI
Venue
2015
10.4018/IJSSE.2015070103
Periodicals
Field
DocType
Volume
Security testing,Application security,Computer science,Computer security,Threat model,Security service,Web application security,Security information and event management,Countermeasure (computer),Threat
Journal
6
Issue
ISSN
Citations 
3
1947-3036
0
PageRank 
References 
Authors
0.34
1
3
Name
Order
Citations
PageRank
bouchaib falah110.70
Mohammed Akour254.81
Samia Oukemeni300.34