Showing posts with label testing tools. Show all posts
Showing posts with label testing tools. Show all posts

Friday, February 27, 2009

What about Test Automation?

Please note that this article has been already posted in previous entries. It was some technical reasons which required to re-post it. Sorry for this.


According to the Wikipedia Test automation is a process of writing a computer program to do testing that would otherwise need to be done manually.

Test automation has come a long way in the past 20 years. The first test tools provided with a simple capture/playback capabilities: recording and playing keystrokes, then capturing and comparing screens. While simple to create, these tests proved almost impossible to maintain, and capture/playback tools were eventually replaced by more powerful and flexible test scripting tools. But those the first automated tools required extensive development skills and efforts to fulfill which in turn made Test automation process quite expensive while not necessarily improving maintainability. Moreover individualized scripting approaches, accompanied with lack of documentation resulted in obsolescence or rewrites script libraries comprising tens of thousands or more lines of code.

All those facts produced a doubtful reputation of Test Automation as a tool for visionaries, and automation tools were perceived as under-utilized, (20-40% usage model). Moreover Software Testing in the era of mainframe systems was merely executing a series of steps manually and punching key strokes as an attempt to break the application.

That era was followed by the event-driven client-server environment in which applications were deployed in various hardware platforms in conjunctions with other applications. As a result the scope of testing has increased as failures and unexpected behaviors have become more prominent.

Recent development of new web-applications with multi-layered structure and complex business logic further increased potential fields for failure. New emerging technologies such as SOA, web services and SaaS along with tendency of Web applications to move toward integrity of business operations to a large audience of users are significantly change the trends in application testing.

An underestimation of the significance of engagement software testing into Analysis and Design phases has lead to business requirements and functional designs which do not meet key criteria for testable systems. The need to develop quality applications in less time and cost will require more structured and automated analysis and design techniques, with Static Testing becoming “automated” and built as part of the analysis and design requirements capture tools.

Automation and “robot” driven testing techniques will be more important and add more value as we move into technologies that support the businesses in their goals to deliver products and services to the market as rapidly as possible, with minimal risks.

Test automation will become more essential to maintaining a technological edge and controlling costs by reducing capital expenses from equipment sharing, improved ability to trace problems, and reduced complexity. It enable companies to get products to market faster at a time when head count may be shrinking.

Thursday, January 22, 2009

Top 25 Programming Errors for Software Testing

Recently experts from more than 30 US and international cyber security organizations announced the consensus list of the Top 25 programming errors that lead to security bugs and that enable cyber espionage and cyber crime. Most of these errors are not well understood and accepted by programmers; their avoidance is not widely taught by computer science programs; and their presence is frequently not tested by organizations developing software for sale.
The impact of these errors is a tremendous. Just two of them led to more than 1.5 million web site security breaches during 2008 - and those breaches infected the computers of people who visited those web sites, turning their computers into zombies.

Among people and organizations cooperated in the project there are respected security experts who come from leading organizations ranging from Symantec and Microsoft, to DHS's National Cyber Security Division, NSA's Information Assurance Division, the University of California at Davis and Purdue University. The initiative was managed by The MITRE and the SANS Institute, financial support came from the US Department of Homeland Security's National Cyber Security Division.

Despite there were some heated discussions the experts came quickly to agreement. "When facing a huge application portfolio that could contain many thousands of instances of over 700 different types of weaknesses, knowing where to start is a daunting task. Says Jeff Williams, Aspect Security CEO and The OWASP Foundation Chair, "Done right, stamping out the CWE Top 25 can not only make you significantly more secure but can cut your software development costs."

The Office of the Director of National Intelligence expressed its support saying, "We believe that integrity of hardware and software products is a critical element of cybersecurity. Creating more secure software is a fundamental aspect of system and network security, given that the federal government and the nation's critical infrastructure depend on commercial products for business operations. The Top 25 is an important component of an overall security initiative for our country. We applaud this effort and encourage the utility of this tool through other venues such as cyber education."

Software testing tools will use the Top 25 in their evaluations and provide scores for the level of secure coding in software being tested. In parallel with this announcement, on January 12, one of the leading software testing vendors is announcing that its software will be able to test for and report on the presence of a large fraction of the Top 25 Errors. Application development teams will use such testing software during the development process.



Prepared by TestLabs of Mirasoft Group

Based on SANS Publications