Abstract: In this paper, we present an application of combinatorial security testing to the well-known anonymity network Tor. Rigorous testing of the Tor network is important to evaluate not only its functionality, but also the security it provides to its users. However, such testing efforts are facing challenges including accurate modelling as well as creation of automated and security-focused test oracles. We argue that combinatorial test sets fulfilling coverage criteria can be used to enhance and augment currently employed testing approaches of Tor in practice. Results from a case study demonstrate that combinatorial methods are a promising avenue for security testing of the Tor anonymity network client.
Loading