欢迎访问中国科学院大学学报,今天是

中国科学院大学学报 ›› 2007, Vol. 24 ›› Issue (3): 300-306.DOI: 10.7523/j.issn.2095-6134.2007.3.005

• 论文 • 上一篇    下一篇

一个基于安全模型的测试用例生成工具

黄 亮 冯登国 张 敏   

  1. 中国科学院软件研究所信息安全实验室,北京 100080;

    中国科学院研究生院,北京 100039

  • 收稿日期:1900-01-01 修回日期:1900-01-01 发布日期:2007-05-15

A generation tool of test case based on security model

HUANG Liang, FENG Deng-Guo, ZHANG Min   

  1. The State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Science, Beijing 100080;

    The Graduate School of the Chinese Academy of Science, Beijing 100039

  • Received:1900-01-01 Revised:1900-01-01 Published:2007-05-15

摘要: 在基于安全评估标准的安全数据库管理系统(Security Database Management System, SDBMS)的安全功能测评中,存在的困难问题之一就是缺乏合适的测试用例.而目前基于安全产品形式化规约的测试用例自动生成方法并不能完全适用于这种需要.因为包括SDBMS在内的大多数信息安全产品的系统规约并不能真实的反映现实系统的行为,系统中的操作除了要完成其预定的功能外,同时还必须满足安全产品安全策略的约束.本文采用了基于安全产品安全策略模型的测试用例自动生成方法,设计并实现了一个测试用例自动化生成工具——CaseBuilder.该工具可针对SDBMS快速生成能够满足产品安全策略测试要求的测试用例集.

关键词: 测试用例, 信息安全产品测评, 类型划分, 安全策略模型

Abstract: During the security evaluation of security products, one of the difficulties is the lack of proper test cases. Current automatic test case generation tools cannot completely solve the problem. Because, most specifications of information security products such as the Secure Database Management System (SDBMS) cannot reflect the systems’ real behavior. Besides the requirements of the product specification, the system must also satisfy the requirements of the security policies. In this paper, we present the design and implementation of CaseBuilder, an automatic test case generating tool, which has adopted a test case generating method based on product’s security policies. As the result of prototyping, CaseBuilder can generate test cases for SDBMS effectively, which can satisfy the testing requirement of security policy model well.

Key words: test case, evaluation of security product, type-based partition, security policy model

中图分类号: