Invention Grant
- Patent Title: Security testing for software applications
- Patent Title (中): 软件应用的安全测试
-
Application No.: US13951837Application Date: 2013-07-26
-
Publication No.: US09483648B2Publication Date: 2016-11-01
- Inventor: Cedric Hebert , Keqin Li
- Applicant: Cedric Hebert , Keqin Li
- Applicant Address: DE Walldorf
- Assignee: SAP SE
- Current Assignee: SAP SE
- Current Assignee Address: DE Walldorf
- Agency: Brake Hughes Bellermann LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; G06F21/57

Abstract:
A mapping engine may be used to determine an attack model enumerating software attacks, the software attacks being represented by linked attack components, and may be used to determine a software architecture to be tested, the software architecture being represented by linked architectural components in an architecture diagram. The mapping engine may then associate each attack component and each architectural component with at least one attack tag characterizing attack requirements. A global test plan generator may be used to determine an attack test model, including associating attack components with corresponding architectural components, based on associated attack tags, and may thus generate attack test workflows from the attack test model, to thereby test the software architecture.
Public/Granted literature
- US20150033346A1 SECURITY TESTING FOR SOFTWARE APPLICATIONS Public/Granted day:2015-01-29
Information query