安全测试是为软件安全的一种关键技术。严峻的结果能反映在软件测试和软件安全之间的关系,并且他们能为评估和改善软件安全帮助程序设计者。然而,由数学描述在功能的测试和软件 nonfunctional 安全索引的软件的结果之间的关系是困难的。在这份报纸,我们基于主要部件分析和 multiattribute 用途理论建议一个数学模型(MSMAM ) 。这个模型能由分析功能的测试的使量子化的结果得到 nonfunctional 安全索引。它能也评估软件安全并且在软件测试的进程指导严峻的资源的有效分配。MSMAM 的可行性和有效性被实验验证。
Security testing is a key technology for software security.The testing results can reflect the relationship between software testing and software security,and they can help program designers for evaluating and improving software security.However,it is difficult to describe by mathematics the relationship between the results of software functional testing and software nonfunctional security indexes.In this paper,we propose a mathematics model(MSMAM) based on principal component analysis and multiattribute utility theory.This model can get nonfunctional security indexes by analyzing quantized results of functional tests.It can also evaluate software security and guide the effective allocation of testing resources in the process of software testing.The feasibility and effectiveness of MSMAM is verified by experiments.