Sie sind auf Seite 1von 2

M ITEA 2 Magazine September 2013 no.

16

Innovation Reports

DIAMONDS ISN
(ITEA 2 ~ 09018) (ITEA 2 ~ 09034)

Security-testing regime for interconnected software- Accelerating the use of standardised wireless
based systems and networks. technologies for systems monitoring and
management.

DIAMONDS
(ITEA 2 09018)

Ina Schieferdecker, Fraunhofer FOKUS,


Germany

Security-testing regime for interconnected


software-based systems and networks

Current security testing is based mainly on audits of processes, systems and networks but this still lacks generic security models and systematic testing

approaches that allow risk-oriented semi-automated analysis. The basic aim of the ITEA 2 DIAMONDS project was to produce an effective methodology capable

of strengthening the practices of security testing commonly used in computer science and various industrial areas.

Nowadays open networks are taken for granted yet MODEL-BASED TESTING FOR SECURITY WEAKNESSES networked systems, as in banking, smart cards,
this continuous interconnection and data-sharing are Against this background, DIAMONDS developed a information technology, software-defined radio and
vulnerable to a growing number of security threats from series of systematic, model-based risk analysis, test defence electronics, are a high priority. By deriving
both internal and external sources. In sectors such as and monitoring approaches for the security testing of common principles and methods, efficient security
transport with train control systems, medical patient care, software systems with advanced model-based security- testing methods relevant to a swathe of industries can
automotive with car-to-infrastructure communications testing methods enabling the early identification of be derived. The DIAMONDS security-test methodology
and mobile telecommunications, there are safety-critical design vulnerabilities and underpinning a focus on the is adaptable to different domain security standards,
implications. Failures can endanger human lives and the efficient testing of security aspects. enables risk-analysis oriented test generation and
environment, implying serious damage to industrial and underpins risk assessments by evaluation of test
social infrastructures, jeopardising confidentiality and The consortium focused on the particular issue results. This industrial-scale European security-test
privacy, or undermine the viability of whole business of testing networked systems for susceptibility to methodology has been demonstrated on security-
sectors. It is common knowledge that the security of most malice, error or mischance, helping to build trust critical systems in a variety of application domains.
systems is directly related to the quality of the underlying in such systems by enabling them to demonstrate
software software defects lie at the root of over 90% of their robustness and fault-tolerance in the face of INNOVATIONS FOR FORMAL SECURITY TESTING
software security incidents. such attacks. Security issues with industrial-scale The four main security-testing method innovations

18 Innovation reports DIAMONDS - ISN


M ITEA 2 Magazine September 2013 no. 16

developed are focused on building a pre-standard for for the case study needs to be constantly improved As a result of this ITEA 2 project, developers will
model-based security testing to represent the enabling and adapted. In order to guarantee that the project benefit by being able to test software for vulnerabilities
technology necessary for the introduction of formal remained innovative with respect to other advances and thus prevent their introduction to the software
security testing in industry: in the security testing area, the partners maintained cycle in the first place; systems integrators, testers,
a state-of-the-art, addressing and changing objectives software quality assurers and software buyers will
Advanced model-based security testing methods as necessary. In addition, DIAMONDS developed the be able to evaluate the quality of software before
which combine different techniques to obtain Security Testing Improvement Profile (STIP) approach, using it, process owners will be able to improve their
improved results applicable to multi-domain that is dedicated to assess security testing processes. security testing analysis and testing processes, and
security The STIP approach has been used to evaluate all researchers will be able to investigate and establish
Development of autonomous testing techniques of the DIAMONDS case studies. It demonstrated new knowledge in systems testing.
based on automatic monitoring
to improve the resilience of SUCCESSFUL EXPLOITATION
dynamically evolving systems The success of the DIAMONDS
Pre-standardisation work on multi- project, underlined by two successive
domain security test methodologies achievement awards at the ITEA 2 &
and test patterns, allowing ARTEMIS Co-summits in 2011 and
DIAMONDS to offer interoperable 2012, is evident in the exploitation of
security test techniques and tools new commercial products including
An open-source platform for security- Codenomicon (new platform release,
test tool integration to provide a several fuzzing test suites), Montimage
common platform and single user (Montimage Monitoring Core),
interface for various test tools, as Smartesting (security-requirements
well as a single tracing and reporting driven test generation), Testing
interface. Technologies (TTCN-3 Fuzz Testing
Extensions) and Dornier Consulting
Through these innovations DIAMONDS (Atoms Security Testing Module).
will strengthen the practices of security Furthermore, DIAMONDS generated
testing, stimulate a wider range of open-source products and product
use of security testing in projects in updates, and FOKUS (Fuzzino,
different domains and help improve Tracebility Platform for RBST) as
the quality, with respect to security, enabled the adoption of methods in
of the systems developed, reducing the production environment (Giesecke
the security risks and the risk-related & Devrient CORAS, METSO
costs during operation. Losses incurred are due not substantial improvements in all case studies due to Network Hoover and Thales combination of active &
only to the consequences of a security breach but also the innovations of the project. passive testing) along with new research projects such as
to the effort needed to repair the deployed systems FOKUS, SINTEF and Smartesting.
and the loss of confidence in the systems concerned Among the case studies in such domains as banking,
(e.g. drop in vendor stock values). Productivity will radio protocol, automotive, telecom and industrial A EUROPEAN GUARANTEE
also be improved by accelerating the testing process, automation were risk-based security testing, advanced A formal security-testing regime for European
increasing the confidence in a system when it is fuzz testing, model-based behavioural fuzzing active software will benefit software designers, developers
modified and eliminating the repetitive tasks needed testing, integration of model-based test generation and vendors of all kinds. Rather than providing timely
when manually testing the resilience of a system. and monitoring, autonomous testing methods, and patches to buggy software, developers will be able
open-source tools for security testing. Furthermore, to find vulnerabilities before hackers exploit them.
CASE STUDIES by developing an open-source platform for security Above all, there is a growing need to evaluate software
Key to quantifying the success of the DIAMONDS test tool integration, DIAMONDS provides a common coming from unknown or little-known European
innovations and steering the project came in the platform, giving the user a single-user interface sources for vulnerabilities, especially those which
shape of use cases through questionnaires and towards various test tools as well as a single tracing could allow malicious entities to penetrate systems
interviews with the persons involved. The criteria and reporting interface to have concise report from the or their connected networks. A European solution
included estimation of cost savings, productivity various tools. This platform will support the integration designed by European actors will present a certain
gains, trust improvement and overall impact of the of testing modules from various vendors and the standard and a certain guarantee to market actors and
methods introduced. The information gathered was open-source community developed specifically for the administrations around the world that wish to preserve
analysed and conclusions were drawn to evaluate platform as well as integration of existing tools. The their systems, their data privacy and their sovereignty.
the work and provide feedback on the technical platform is available for all security testing vendors and
work packages. Iterating this process throughout open-source community members as integration point for more information
the project helped the methods and tools developed for their tools. www.itea2-diamonds.org

Innovation reports DIAMONDS - ISN 19

Das könnte Ihnen auch gefallen