{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,11]],"date-time":"2025-12-11T20:50:44Z","timestamp":1765486244800,"version":"3.40.3"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030009786"},{"type":"electronic","value":"9783030009793"}],"license":[{"start":{"date-parts":[[2018,9,28]],"date-time":"2018-09-28T00:00:00Z","timestamp":1538092800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-00979-3_27","type":"book-chapter","created":{"date-parts":[[2018,9,27]],"date-time":"2018-09-27T08:55:41Z","timestamp":1538038541000},"page":"267-276","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Fuzz Test Case Generation for Penetration Testing in Mobile Cloud Computing Applications"],"prefix":"10.1007","author":[{"given":"Ahmad Salah","family":"Al-Ahmad","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hasan","family":"Kahtan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,9,28]]},"reference":[{"key":"27_CR1","doi-asserted-by":"crossref","unstructured":"Geer, D., Harthorne, J.: Penetration testing: a duet. In: 18th Annual Computer Security Applications Conference. IEEE, Las Vegas (2002)","DOI":"10.1109\/CSAC.2002.1176290"},{"key":"27_CR2","doi-asserted-by":"crossref","unstructured":"Xiong, P., Peyton, L.: A model-driven penetration test framework for Web applications. In: Eighth Annual International Conference on Privacy, Security and Trust (PST). IEEE, Ottawa (2010)","DOI":"10.1109\/PST.2010.5593250"},{"issue":"2","key":"27_CR3","first-page":"87","volume":"5","author":"W Xu","year":"2016","unstructured":"Xu, W., Groves, B., Kwok, W.: Penetration testing on cloud\u2014case study with owncloud. Glob. J. Inf. Technol. 5(2), 87\u201394 (2016)","journal-title":"Glob. J. Inf. Technol."},{"key":"27_CR4","doi-asserted-by":"crossref","unstructured":"Goel, J.N., et al.: Ensemble based approach to increase vulnerability assessment and penetration testing accuracy. In: 2016 International Conference on Innovation and Challenges in Cyber Security (ICICCS-INBUSH). IEEE (2016)","DOI":"10.1109\/ICICCS.2016.7542303"},{"key":"27_CR5","doi-asserted-by":"crossref","unstructured":"Zhao, J., et al.: Penetration testing automation assessment method based on rule tree. In: IEEE International Conference on Cyber Technology in Automation, Control, and Intelligent Systems (CYBER), Shenyang, China (2015)","DOI":"10.1109\/CYBER.2015.7288225"},{"key":"27_CR6","unstructured":"Deptula, K.: Automation of cyber penetration testing using the detect, identify, predict, react intelligence automation model. In: Postgraduate School. Naval Postgraduate School, Monterey, p. 139 (2013)"},{"key":"27_CR7","doi-asserted-by":"crossref","unstructured":"Xing, B., et al.: Design and implementation of an XML-based penetration testing system. In: International Symposium on Intelligence Information Processing and Trusted Computing (IPTC). IEEE, Huanggang (2010)","DOI":"10.1109\/IPTC.2010.109"},{"key":"27_CR8","doi-asserted-by":"crossref","unstructured":"Mainka, C., Somorovsky, J., Schwenk, J.: Penetration testing tool for web services security. In: 8th IEEE World Congress on Servicess. IEEE, Honolulu (2012)","DOI":"10.1109\/SERVICES.2012.7"},{"key":"27_CR9","doi-asserted-by":"crossref","unstructured":"Halfond, W.G., Choudhary, S.R., Orso, A.: Penetration testing with improved input vector identification. In: International Conference on Software Testing Verification and Validation. IEEE, Lillehammer (2009)","DOI":"10.1109\/ICST.2009.26"},{"issue":"2","key":"27_CR10","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1353-4858(13)70028-X","volume":"2013","author":"G Jones","year":"2013","unstructured":"Jones, G.: Penetrating the cloud. Netw. Secur. 2013(2), 5\u20137 (2013)","journal-title":"Netw. Secur."},{"issue":"5","key":"27_CR11","first-page":"10","volume":"5","author":"B-H Kang","year":"2008","unstructured":"Kang, B.-H.: About effective penetration testing methodology. J. Secur. Eng. 5(5), 10 (2008)","journal-title":"J. Secur. Eng."},{"issue":"6","key":"27_CR12","first-page":"43","volume":"2","author":"R LaBarge","year":"2013","unstructured":"LaBarge, R., McGuire, T.: Cloud penetration testing. Int. J. Cloud Comput. Serv. Arch. (IJCCSA) 2(6), 43\u201362 (2013)","journal-title":"Int. J. Cloud Comput. Serv. Arch. (IJCCSA)"},{"issue":"3","key":"27_CR13","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4018\/jitwe.2012070101","volume":"7","author":"Ahmad Al-Ahmad","year":"2012","unstructured":"Al-Ahmad, A., Abu Ata, B., Wahbeh, A.: Pen testing for web applications. Int. J. Inf. Technol. Web Eng. (IJITWE), 7(3), 1\u201313 (2012)","journal-title":"International Journal of Information Technology and Web Engineering"},{"key":"27_CR14","doi-asserted-by":"crossref","unstructured":"Schneider, M., et al.: Online Model-based behavioral fuzzing. In: IEEE Sixth International Conference on Software Testing, Verification and Validation Workshops (ICSTW). IEEE, Luxembourg (2013)","DOI":"10.1109\/ICSTW.2013.61"},{"key":"27_CR15","doi-asserted-by":"crossref","unstructured":"Schneider, M., et al.: Behavioral fuzzing operators for UML sequence diagrams. Springer (2013)","DOI":"10.1007\/978-3-642-36757-1_6"},{"key":"27_CR16","unstructured":"de Graaf, M.: Intelligent fuzzing of web applications. In: Software Engineering. Universiteit van Amsterdam: Digital Academic Repository \u2013 UBA, University of Amsterdam (2009)"},{"key":"27_CR17","unstructured":"F\u00e4rnlycke, I.: An approach to automating mobile application testing on Symbian smartphones: functional testing through log file analysis of test cases developed from use cases. In: School of Information and Communication Technology (ICT), KTH Royal Institute Of Technology (2013). Open Access in DiVA"},{"key":"27_CR18","doi-asserted-by":"crossref","unstructured":"Karami, M., et al.: Behavioral analysis of android applications using automated instrumentation. In: IEEE 7th International Conference on Software Security and Reliability-Companion (SERE-C), Gaithersburg, Maryland, USA (2013)","DOI":"10.1109\/SERE-C.2013.35"},{"key":"27_CR19","doi-asserted-by":"crossref","unstructured":"Mahmood, R., et al.: A whitebox approach for automated security testing of Android applications on the cloud. In: Proceedings of the 7th International Workshop on Automation of Software Test (AST). IEEE, Zurich (2012)","DOI":"10.1109\/IWAST.2012.6228986"},{"key":"27_CR20","doi-asserted-by":"crossref","unstructured":"Yang, Y., et al.: A model-based fuzz framework to the security testing of TCG software stack implementations. In: International Conference on Multimedia Information Networking and Security (MINES). IEEE, Hubei (2009)","DOI":"10.1109\/MINES.2009.111"},{"key":"27_CR21","doi-asserted-by":"crossref","unstructured":"Kaur, S. Sohal, H.S.: Hybrid application partitioning and process offloading method for the mobile cloud computing. In: Proceedings of the First International Conference on Intelligent Computing and Communication. Springer, Singapore (2017)","DOI":"10.1007\/978-981-10-2035-3_10"},{"issue":"1","key":"27_CR22","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1016\/j.jnca.2014.08.011","volume":"47","author":"M Shiraz","year":"2015","unstructured":"Shiraz, M., et al.: A study on the critical analysis of computational offloading frameworks for mobile cloud computing. J. Netw. Comput. Appl. 47(1), 47\u201360 (2015)","journal-title":"J. Netw. Comput. Appl."},{"key":"27_CR23","doi-asserted-by":"crossref","unstructured":"Rastogi, V., Chen, Y., Enck, W.: Appsplayground: automatic security analysis of smartphone applications. In: Proceedings of the Third ACM Conference on Data and Application Security and Privacy. ACM, New Orleans (2013)","DOI":"10.1145\/2435349.2435379"},{"key":"27_CR24","doi-asserted-by":"crossref","unstructured":"Wassermann, G., et al.: Dynamic test input generation for web applications. In: Proceedings of the International Symposium on Software Testing and Analysis. ACM, Seattle (2008)","DOI":"10.1145\/1390630.1390661"},{"key":"27_CR25","unstructured":"Nageswaran, S.: Test effort estimation using use case points. In: Quality Week, San Francisco, California, USA (2001)"},{"key":"27_CR26","unstructured":"Mendez, X.: SQL injection fuzz strings (from wfuzz tool) (2014). https:\/\/wfuzz.googlecode.com\/svn\/trunk\/wordlist\/Injections\/SQL.txt . Accessed 11 Sept 2015"},{"key":"27_CR27","doi-asserted-by":"crossref","unstructured":"Huang, D., et al.: MobiCloud: building secure cloud framework for mobile computing and communication. In: Fifth IEEE International Symposium on Service Oriented System Engineering (SOSE). IEEE, Nanjing (2010)","DOI":"10.1109\/SOSE.2010.20"},{"issue":"4","key":"27_CR28","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1109\/MC.2010.98","volume":"43","author":"K Kumar","year":"2010","unstructured":"Kumar, K., Lu, Y.-H.: Cloud computing for mobile users: can offloading computation save energy? IEEE Comput. Soc. 43(4), 51\u201356 (2010)","journal-title":"IEEE Comput. Soc."},{"key":"27_CR29","doi-asserted-by":"crossref","unstructured":"Zhang, J., Sun, D., Zhai, D.: A research on the indicator system of cloud computing security risk assessment. In: International Conference on Quality, Reliability, Risk, Maintenance, and Safety Engineering (ICQR2MSE). IEEE, Chengdu (2012)","DOI":"10.1109\/ICQR2MSE.2012.6246200"},{"key":"27_CR30","doi-asserted-by":"crossref","unstructured":"Giurgiu, I., et al.: Calling the cloud: enabling mobile phones as interfaces to cloud applications. In: Middleware, pp. 83\u2013102. Springer, New York (2009)","DOI":"10.1007\/978-3-642-10445-9_5"},{"key":"27_CR31","doi-asserted-by":"crossref","unstructured":"Kovachev, D. Klamma, R.: Beyond the client-server architectures: a survey of mobile cloud techniques. In: 1st IEEE International Conference on Communications in China Workshops (ICCC). IEEE, Beijing (2012)","DOI":"10.1109\/ICCCW.2012.6316468"},{"issue":"4","key":"27_CR32","first-page":"379","volume":"36","author":"Y Singh","year":"2012","unstructured":"Singh, Y., et al.: Systematic literature review on regression test prioritization techniques. Inform. (Slov.) 36(4), 379\u2013408 (2012)","journal-title":"Inform. (Slov.)"},{"key":"27_CR33","doi-asserted-by":"crossref","unstructured":"Budgen, D., Brereton, P.: Performing systematic literature reviews in software engineering. In: Proceedings of the 28th International Conference on Software Engineering. ACM, Shanghai (2006)","DOI":"10.1145\/1134285.1134500"},{"issue":"4","key":"27_CR34","doi-asserted-by":"publisher","first-page":"571","DOI":"10.1016\/j.jss.2006.07.009","volume":"80","author":"P Brereton","year":"2007","unstructured":"Brereton, P., et al.: Lessons from applying the systematic literature review process within the software engineering domain. J. Syst. Softw. 80(4), 571\u2013583 (2007)","journal-title":"J. Syst. Softw."},{"key":"27_CR35","unstructured":"Zeisberger, S., Irwin, B.: A fuzz testing framework for evaluating and securing network applications. In: the Annual Southern Africa Telecommunication Networks and Applications Conference (SATNAC), London, UK (2011)"},{"key":"27_CR36","doi-asserted-by":"crossref","unstructured":"Shahriar, H., North, S., Mawangi, E.: Testing of memory leak in android applications. In: IEEE 15th International Symposium on High-Assurance Systems Engineering (HASE). IEEE, Miami (2014)","DOI":"10.1109\/HASE.2014.32"},{"issue":"2","key":"27_CR37","first-page":"724","volume":"4","author":"M Kaushik","year":"2014","unstructured":"Kaushik, M., Ojha, G.: Attack penetration system for SQL injection. Int. J. Adv. Comput. Res. 4(2), 724 (2014)","journal-title":"Int. J. Adv. Comput. Res."},{"key":"27_CR38","doi-asserted-by":"crossref","unstructured":"Fertig, T., Braun, P.: Model-driven testing of restful apis. In: Proceedings of the 24th International Conference on World Wide Web. ACM (2015)","DOI":"10.1145\/2740908.2743045"},{"key":"27_CR39","unstructured":"Zhu, Z.: Automated penetration testing for PHP web applications, Georgia Institute of Technology, pp. 48, November 2016"},{"key":"27_CR40","doi-asserted-by":"crossref","unstructured":"Liu, L., et al.: An inferential metamorphic testing approach to reduce false positives in SQLIV penetration test. In: IEEE 41st Annual Computer Software and Applications Conference (COMPSAC) (2017)","DOI":"10.1109\/COMPSAC.2017.276"},{"key":"27_CR41","doi-asserted-by":"crossref","unstructured":"Al-Ahmad, A.S., Aljunid, S.A., Sani, A.S.A.: Mobile cloud computing testing review. In: International Conference on Advanced Computer Science Applications and Technologies (ACSAT). IEEE, Kuala Lumpur (2013)","DOI":"10.1109\/ACSAT.2013.42"},{"issue":"06","key":"27_CR42","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4236\/jcc.2017.56001","volume":"5","author":"A Paranjothi","year":"2017","unstructured":"Paranjothi, A., Khan, M.S., Nijim, M.: Survey on three components of mobile cloud computing: offloading, distribution and privacy. J. Comput. Commun. 5(06), 1 (2017)","journal-title":"J. Comput. Commun."}],"container-title":["Advances in Intelligent Systems and Computing","Intelligent Computing &amp; Optimization"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-00979-3_27","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,24]],"date-time":"2019-10-24T20:14:30Z","timestamp":1571948070000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-00979-3_27"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,9,28]]},"ISBN":["9783030009786","9783030009793"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-00979-3_27","relation":{},"ISSN":["2194-5357","2194-5365"],"issn-type":[{"type":"print","value":"2194-5357"},{"type":"electronic","value":"2194-5365"}],"subject":[],"published":{"date-parts":[[2018,9,28]]},"assertion":[{"value":"ICO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Intelligent Computing & Optimization","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Pattaya","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Thailand","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"5 October 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ico2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.icico.info\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}