Is safe Cloud Computing Pie in the Sky?

Is safe Cloud Computing Pie in the Sky?

ID: 336278

Safe Cloud Computing is no Cloud Cuckoo Land

(firmenpresse) - The integration of digital expert knowledge and automation of risk analyses can greatly improve software test procedures and make cloud computing more secure. This is shown by the latest results of a project by the Austrian Science Fund FWF on the quality assurance of security critical systems which has just been published. The results provide a platform for what are known as non-functional security tests. These attempt to identify weaknesses in software which do not arise directly from the execution of the program – and play an increasingly important role for cloud computing. The recently developed platform allows such tests to be automated further and made more user-friendly.

Software developers frequently experience nasty surprises: Even after long and successful use of cloud programs, unexpected weaknesses can suddenly emerge. In fact, cloud programs are particularly susceptible to this. Not because they are badly written, but because they have many interfaces which are continually adapted. These require functionalities that go well beyond the actual running of the program and are dependent on third-party systems. Non-functional security tests, as they are called, may be able to test these aspects, but the conventional methods of quality assurance are often defeated by the complexity of the requirements. Researchers at the University of Innsbruck have now presented a platform which can significantly improve non-functional tests.

To Test is The Best
The main success criteria of this platform, which was developed by a team led by Prof. Ruth Breu, Head of the Institute of Computer Science, are the integration of expert knowledge as well as automation of the processes for risk analysis. The importance of the integration of formalised expert knowledge about weak points in software is strikingly expressed by Prof. Breu: "In the year 2012 alone, 9,762 previously unknown security vulnerabilities were registered in the Open Source Vulnerability Database, a globally accessible database for the administration of knowledge about security vulnerabilities in software. But in fact, the causes of many of these security vulnerabilities have been known for a long time. They could therefore have been avoided at the point when the software was developed. Thus optimised non-functional tests should make use of such existing knowledge. That is exactly what our procedure does."





To this effect, the team headed by Prof. Breu, Dr. Michael Felderer and Philipp Zech formalise such knowledge to make it available for subsequent automatic risk analysis. These analyses then result in risk profiles for the systems to be tested, which are used for the production of executable security tests. This involves the application of modern programming languages such as Scala and ASP, as well as model-based techniques. "The problem with earlier non-functional security tests is the sheer endless number of possibilities for error. Previous attempts to master this situation involved human expert knowledge, e.g. for penetration tests. But the approach we selected now allows a structured and automated test procedure", explains Prof. Breu with reference to this automated risk analysis process.

Practical Test
Prof. Breu continues: "Our work initially tended to be guided by theory. But we also wanted to demonstrate the practical relevance of our deliberations. So we performed real-life tests which checked reactions to common problem situations such as SQL injection attacks." Within the framework of the currently published work, programs written by the researchers were initially relied upon to do this. However, for some time now, Prof. Breu's team has also been using publicly available test systems. With impressive results: Up to 90 per cent of all weak points can currently be identified reliably.

Overall, the results of this FWF project represent significant progress for the future quality assurance of security critical systems – a result which once more confirms the significance of basic research work for the smooth functioning of our daily life.

Image and text available from Monday, 15 September 2014, from 10.00 am CET at:
http://www.fwf.ac.at/en/research-in-practice/project-presentations/2014/pv201409/

Original publication: P. Zech, M. Felderer, B. Katt and R. Breu: Security Test Generation by Answer Set Programming. The Eighth International Conference on Software Security and Reliability (SERE 2014), IEEE, 2014

Weitere Infos zu dieser Pressemeldung:

Themen in dieser Pressemitteilung:


Unternehmensinformation / Kurzprofil:

FWF Austrian Science Fund

The Austrian Science Fund (FWF) is Austria's central funding organization for basic research.



PresseKontakt / Agentur:

Scientific Contact:
Prof. Ruth Breu
University of Innsbruck
Institute of Computer Science
Technikerstrasse 21a/2
6020 Innsbruck, Austria
T +43 / 512 / 507 - 53200
E ruth.breu(at)uibk.ac.at

Austrian Science Fund FWF:
Marc Seumenicht
Haus der Forschung
Sensengasse 1
1090 Vienna, Austria
T +43 / 1 / 505 67 40 - 8114
E marc.seumenicht(at)fwf.ac.at

Copy Editing & Distribution:
PR&D – Public Relations for Research & Education
Mariannengasse 8
1090 Vienna, Austria
T +43 / 1 / 505 70 44
E contact(at)prd.at
W http://www.prd.at



drucken  als PDF  an Freund senden  Media Asset Management, editing projects and task management seamlessly integrated Go for glory with the Champions League Predictor app!
Bereitgestellt von Benutzer: PRD
Datum: 15.09.2014 - 13:58 Uhr
Sprache: Deutsch
News-ID 336278
Anzahl Zeichen: 4636

contact information:
Contact person: Till C. Jelitto
Town:

Wien


Phone: +43 / 1 / 505 70 44

Kategorie:

Computer & Software


Typ of Press Release: Erfolgsprojekt
type of sending: Veröffentlichung
Date of sending: 15.09.2014

Diese Pressemitteilung wurde bisher 322 mal aufgerufen.


Die Pressemitteilung mit dem Titel:
"Is safe Cloud Computing Pie in the Sky?"
steht unter der journalistisch-redaktionellen Verantwortung von

FWF (Nachricht senden)

Beachten Sie bitte die weiteren Informationen zum Haftungsauschluß (gemäß TMG - TeleMedianGesetz) und dem Datenschutz (gemäß der DSGVO).

Opera and politics ...

The Vienna State Opera is an institution, an icon of high culture, far removed from everyday concerns. Or is it? With the support of the Austrian Science Fund FWF, a research team from Vienna examined the interaction between prevailing political cont ...

A career depends on many factors ...

What factors influence someone's career and how much have they changed over time? What are the expectations people have for their careers today? A long-term study funded by the Austrian Science Fund FWF explores the evolution of managerial caree ...

Alle Meldungen von FWF



 

Werbung



Facebook

Sponsoren

foodir.org The food directory für Deutschland
Informationen für Feinsnacker finden Sie hier.

Firmenverzeichniss

Firmen die firmenpresse für ihre Pressearbeit erfolgreich nutzen
1 2 3 4 5 6 7 8 9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z