DBMS Security Audit Function Test Case Generation

叶晓俊,刘泊伶,谢丰,张种斌,李斌
DOI: https://doi.org/10.16511/j.cnki.qhdxxb.2011.10.012
2011-01-01
Abstract:Data base management system(DBMS) security audit conformance testing requires evaluators to design test cases which effectively cover all DBMS security target specifications.This paper describes a DBMS security audit test case generation approach based on security audit specifications using labeled transition system(LTS) modeling.This approach first builds the LTS model for the security audit function components for the DBMS security target(DBMS ST),produces audit event sequences based on the path output from the component behavior model using a heuristic path search algorithm,and generates test scenarios with testing data in a target database for the scenarios according to TOE security constraints to form test case suites.Test with about two hundred test cases were produced using this approach and transformed into scripts through variable configurations or statements.These were run against a national DBMS,during which several security flaws were found.Tests show that this approach can generate useful test cases,which cover all security audit component function test requirements.
What problem does this paper attempt to address?