Open Ended Vulnerability Testing Update

You might also like

Download as ppt, pdf, or txt
Download as ppt, pdf, or txt
You are on page 1of 5

Open Ended Vulnerability Testing

Update

Nelson Hastings
National Institute of Standards and Technology
http://vote.nist.gov

12/9-10/2009 TGDC Meeting


Motivation
 The VVSG 2.0 provides open ended
vulnerability testing (OEVT) as a test
methodology
 Update on research related to OEVT to
support EAC certification program
 Key issues: Cost and Repeatability
12/9-10/2009 TGDC Meeting
Page 2
Research
 Methodologies
 Flaw hypotheses
 Security assertion based hypotheses
 Security fault analysis
 Ad hoc penetration testing
 No one methodology is satisfying, use the
best aspects of each methodology

12/9-10/2009 TGDC Meeting


Page 3
Research
 Keys to Quality OEVT
 Penetration tester experience and expertise
 Input to the testing
 Areas of investigation
 Allocation of resources

12/9-10/2009 TGDC Meeting


Page 4
Next Steps
 Develop OEVT methodology for voting systems
 Based on best features of the different methodologies
 How to use a review panel to help uniformity in OEVT
 Review of OEVT tester qualification
 Provide input during execution of OEVT
 Determining resources needed for OEVT
 Function of system design and implementation quality
 Function of known vulnerabilities

12/9-10/2009 TGDC Meeting


Page 5

You might also like