AST 2023
Mon 15 - Tue 16 May 2023 Melbourne, Australia
co-located with ICSE 2023
Mon 15 May 2023 15:45 - 16:07 at Meeting Room 107 - Testing

Insecure default values in software settings can be exploited by attackers to compromise the system that runs the software. As a countermeasure, there exist security-configuration guides specifying in detail which values are secure. However, most administrators still refrain from hardening existing systems because the system functionality is feared to deteriorate if secure settings are applied. To foster the application of security-configuration guides, it is necessary to identify those rules that would restrict the functionality.

This article presents our approach to use combinatorial testing to find problematic combinations of rules and machine learning techniques to identify the problematic rules within these combinations. The administrators can then apply only the unproblematic rules and, therefore, increase the system’s security without the risk of disrupting its functionality. To demonstrate the usefulness of our approach, we applied it to real-world problems drawn from discussions with administrators at Siemens and found the problematic rules in these cases. We hope that this approach and its open-source implementation motivate more administrators to harden their systems and, thus, increase their systems’ general security.

Mon 15 May

Displayed time zone: Hobart change

15:45 - 17:15
15:45
22m
Talk
Better Safe Than Sorry! Automated Identification of Functionality-Breaking Security-Configuration Rules
AST 2023
Patrick Stöckle Technical University of Munich (TUM) / Siemens AG, Michael Sammereier Technical University of Munich, Bernd Grobauer Siemens AG, Alexander Pretschner Technical University of Munich
Link to publication DOI Pre-print
16:07
22m
Talk
Cross-coverage testing of functionally equivalent programs
AST 2023
Antonia Bertolino National Research Council, Italy, Guglielmo De Angelis CNR-IASI, Felicita Di Giandomenico ISTI-CNR, Francesca Lonetti CNR-ISTI
Pre-print
16:30
22m
Talk
Towards a Review on Simulated ADAS/AD Testing
AST 2023
Yavuz Koroglu Graz University of Technology, Franz Wotawa Graz University of Technology