|
中国科学院研究生院学报 2007
A generation tool of test case based on security model
|
Abstract:
During the security evaluation of security products,one of the difficulties is the lack of proper test cases.Current automatic test case generation tools cannot completely solve the problem.The reason is that most specifications of information security products,such as the Secure Database Management System(SDBMS),cannot reflect the systems' real behaviors.Besides the requirements of the product specification,the system must also satisfy the requirements of the security policies.In this paper,we present the design and implementation of CaseBuilder,an automatic test case generating tool,which has adopted a test case generating method based on the product's security policies.As the result of prototyping,CaseBuilder can generate test cases for SDBMS effectively,which can well satisfy the testing requirements of security policy model.