Home
International Software Testing Conference
Home
About The Conference
Organizers
2007 Security Speakers
2007 Security Testing Talks
2007 Quality Testing
2007 Keynote Speeches
2007 Sponsors
2007 Half-Day Workshops
VERIFY 2007 Conference
Mailing List

Enter your email to receive occasional news about VERIFY 2008.

ST15 Testing Input for Security and Quality using Boundary Value Testing PDF Print E-mail

Penetration testing tools do a good job of finding obvious web errors. But some do so simply, by sending only canned tests (such as 1000 ‘a’s) at the interface. What if your developers’ code resists this folly but still contains more subtle vulnerabilities / errors? In this talk, I’ll present the age-old practice of boundary value testing to help audience members generate more potent test data—data that can even find subtle logic bugs. Then the question becomes, how much evil test data is enough? This session will cover equivalence class partitioning, showing audience members how to select a minimum set of data that maximizes bug-finding potential.

Applying these techniques, testers will become more senior, and more effectively find implementation bugs. These techniques are also a good way to begin adding security to an untrained quality person’s repertoire—immediately adding value.





Digg!Reddit!Del.icio.us!Google!Netscape!Technorati!StumbleUpon!Newsvine!Yahoo!
Last Updated ( Monday, 30 July 2007 )