Hybrid Software Testing System for Risk-Based Input Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integration of functional and security testing in software development is challenging due to disjoint objectives and test environments, leading to increased costs and time in executing these tests independently.
Innovation Solution
A method and system for hybrid testing that assigns risk values to input points of a software unit under test, distinguishing between low and high security risk inputs to provide appropriate test values for functional or security testing, thereby executing a unified security test.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If functional and security testing are executed independently, then each test can be performed with its own specialized methods, but the total cost and time increase
Solution Approach 1:
The patent combines functional testing and security testing into a single hybrid testing process. The system assigns risk values to input points and selectively applies functional or security test values based on these risk assessments, merging two previously separate testing workflows into one unified process that reduces overall testing time while maintaining the specialized strengths of each approach.
Solution Approach 2:
The patent segments the testing process by dividing input points into different risk categories (low risk, medium risk, high risk). Each segment receives appropriate test values based on its risk level, allowing the system to apply functional testing to low-risk inputs and security testing to high-risk inputs within the same overall testing framework.
2Loss of time
If security testing is integrated with functional testing, then cost and time are reduced, but the difficulty of integration increases due to disjoint objectives and test environments
Solution Approach 1:
The patent introduces a risk value assignment mechanism as an intermediary layer between functional testing and security testing. This mediator evaluates each input point and determines whether to apply functional test values or security test values, bridging the gap between the two disparate testing approaches and enabling their integration without direct conflict.
Solution Approach 2:
The patent applies different testing strategies to different parts of the system based on local risk characteristics. Each input point is evaluated individually and assigned appropriate test values based on its specific risk profile, rather than applying a uniform testing approach across all inputs. This allows the system to maintain simplicity while handling the complexity of integrated testing through localized decision-making.
Data Source
AI summary
Embodiments of the present disclosure relate to methods and systems for hybrid testing, combining the optimization features of functional testing brought forth to security testing. One disclosed method may include receiving a list of input points associated with a software unit under test and assigning, by a processor, risk values to the input points based on one or more risk rating factors. The risk values may reflect security risk associated with the input points. The method may further include providing, to the software unit under test, input values indicative of a functional test for input points assigned values reflecting a low security risk and input values indicative of a security test for input points assigned values reflecting a high security risk. The method may further include executing a security test for the software unit under test using the input values.


