Model-Based Security Testing
Ina Schieferdecker (Fraunhofer FOKUS), Juergen Grossmann (Fraunhofer, FOKUS), Martin Schneider (Fraunhofer FOKUS)

TL;DR
This paper surveys model-based security testing (MBST), a systematic approach for specifying, documenting, and automating security test cases, with a focus on recent methods and tools developed in the European DIAMONDS project.
Contribution
It provides a comprehensive overview of MBST techniques, models, and emerging methods, highlighting recent developments and industrial relevance.
Findings
MBST enables high-level security test specification and automation.
Recent methods integrate security modeling with test generation.
European DIAMONDS project advances MBST tools and techniques.
Abstract
Security testing aims at validating software system requirements related to security properties like confidentiality, integrity, authentication, authorization, availability, and non-repudiation. Although security testing techniques are available for many years, there has been little approaches that allow for specification of test cases at a higher level of abstraction, for enabling guidance on test identification and specification as well as for automated test generation. Model-based security testing (MBST) is a relatively new field and especially dedicated to the systematic and efficient specification and documentation of security test objectives, security test cases and test suites, as well as to their automated or semi-automated generation. In particular, the combination of security modelling and test generation approaches is still a challenge in research and of high interest for…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
