P. Krishnan, Jerome Loh, Rebecca O'Donoghue, L. Meinicke
{"title":"Evaluating quality of security testing of the JDK","authors":"P. Krishnan, Jerome Loh, Rebecca O'Donoghue, L. Meinicke","doi":"10.1145/3121245.3121246","DOIUrl":null,"url":null,"abstract":"In this position paper we describe how mutation testing can be used to evaluate the quality of test suites from a security viewpoint. Our focus is on measuring the quality of the test suite associated with the Java Development Kit (JDK) because it provides the core security properties for all applications. We describe the challenges associated with identifying security-specific mutation operators that are specific to the Java model and ensuring that our solution can be automated for large code-bases like the JDK.","PeriodicalId":107820,"journal":{"name":"Proceedings of the 8th ACM SIGSOFT International Workshop on Automated Software Testing","volume":"106 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-09-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 8th ACM SIGSOFT International Workshop on Automated Software Testing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3121245.3121246","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
In this position paper we describe how mutation testing can be used to evaluate the quality of test suites from a security viewpoint. Our focus is on measuring the quality of the test suite associated with the Java Development Kit (JDK) because it provides the core security properties for all applications. We describe the challenges associated with identifying security-specific mutation operators that are specific to the Java model and ensuring that our solution can be automated for large code-bases like the JDK.