期刊文献+

Cloud Platform Based Automated Security Testing System for Mobile Internet

Cloud Platform Based Automated Security Testing System for Mobile Internet
原文传递
导出
摘要 With respect to security, the use of various terminals in the mobile Internet environment is problematic.Traditional terminal testing methods cannot simulate actual testing environments; thus, the test results do not accurately reflect the security of terminals. To address this problem, we designed and developed a cloud platform based automated testing system for the mobile Internet. In this system, virtualization and automation technology are utilized to integrate mobile terminals into the cloud platform as a resource, to achieve a novel cloud service called Testing as a Service(Taa S). The system consists of three functional modules: web front-end module, testing environment module, and automated testing module. We adopted the permeable automated testing tool Metasploit to perform security testing. In our test experiments, we selected 100 apps with diverse vulnerability levels, ranging from secure to vulnerable, to perform a series of functional tests. The experimental results show that this system can correctly test both the number of vulnerable apps and their corresponding vulnerability levels. As such, the designed system can flexibly configure various testing environments for different testing cases or projects, and thereby perform security testing automatically. With respect to security, the use of various terminals in the mobile Internet environment is problematic.Traditional terminal testing methods cannot simulate actual testing environments; thus, the test results do not accurately reflect the security of terminals. To address this problem, we designed and developed a cloud platform based automated testing system for the mobile Internet. In this system, virtualization and automation technology are utilized to integrate mobile terminals into the cloud platform as a resource, to achieve a novel cloud service called Testing as a Service(Taa S). The system consists of three functional modules: web front-end module, testing environment module, and automated testing module. We adopted the permeable automated testing tool Metasploit to perform security testing. In our test experiments, we selected 100 apps with diverse vulnerability levels, ranging from secure to vulnerable, to perform a series of functional tests. The experimental results show that this system can correctly test both the number of vulnerable apps and their corresponding vulnerability levels. As such, the designed system can flexibly configure various testing environments for different testing cases or projects, and thereby perform security testing automatically.
出处 《Tsinghua Science and Technology》 SCIE EI CAS CSCD 2015年第6期537-544,共8页 清华大学学报(自然科学版(英文版)
基金 supported by the National Natural Science Foundation of China (No. 61202431) the National High-Tech Research and Development (863) Program of China (No. 2013AA014702) Beijing Higher Education Young Elite Teacher Project (No. YETP0535) the Open Project Program of Jiangsu High Technology Research Key Laboratory for Wireless Sensor Networks the Scientific Research Foundation for the Returned Overseas Chinese Scholars, Ministry of Education
关键词 automated security testing cloud platform virtuali automated security testing cloud platform virtuali
  • 相关文献

参考文献13

  • 1Lin, Ying-Dar,Chu, Edward T-H,Yu, Shang-Che,Lai, Yuan-Cheng.Improving the Accuracy of Automated GUI Testing for Embedded Systems[J]. IEEE Software . 2014 (1)
  • 2S. Subashini,V. Kavitha.A survey on security issues in service delivery models of cloud computing[J]. Journal of Network and Computer Applications . 2010 (1)
  • 3Songwen Pei,Baifeng Wu,Kun Zhu,Qiang Yu.Novel Software Automated Testing System Based on J2EE[J]. Tsinghua Science & Technology . 2007
  • 4Chien-Hung Liu,Chien-Yu Lu,Shan-Jen Cheng,Koan-Yuh Chang,Yung-Chia Hsiao,Deng-Ming Chu.Capture-Replay Testing for Android Applications. 2014 International Symposium on Computer, Consumer and Control . 2014
  • 5Salaheddin Odeh,Yazid Al-khatib.Computer Resources as a Cloud LabService. IEEE Global Engineering Education Conference (EDUCON) . 2012
  • 6Tommi Takala,Mika katara."Experiences of Systim-Level Model-Based GUI Testing of an Android Application". IEEE International Conference on Software Testing . 2011
  • 7Wipro.Testing as a service. http://taas.wipro.com/index.aspx . 2013
  • 8P.S.Kochhar,F.Thung,N.Nagappan,T.Zimmermann.Understanding the test automation culture of app developers. 2015 IEEE 8th International Conference on-Software Testing,Verification and (Validation ICST) . 2015
  • 9Yi Ce Yun. http://www.yiceyun.com . 2012
  • 10D.Kennedy,J.O’’Gorman,D.Kearns,M.Aharoni.Metasploit:The Penetration Tester’’s Guide. . 2013

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部