Proposing SQL Statement Coverage Metrics

Source: Association for Computing Machinery

Favorite

Free registration required

An increasing number of cyber attacks are occurring at the application layer when attackers use malicious input. These input validation vulnerabilities can be exploited by (among others) SQL injection, cross site scripting, and buffer overflow attacks. Statement coverage and similar test adequacy metrics have historically been used to assess the level of functional and unit testing which has been performed on an application. However, these currently-available metrics do not highlight how well the system protects itself through validation. In this paper, the authors propose two SQL injection input validation testing adequacy metrics: target statement coverage and input variable coverage.
Format:PDF Size:383.60
Date:May 2008