can be a test prioritization, when test sequences or 
test cases are distributed between several classes. In 
functional testing, these classes are usually 
represented by the number of faults or the number of 
mutants that can be killed by a given test case. In the 
case of active trust assessment, test cases can be 
assigned with the scores as the trust levels obtained 
from a SUT. Studying the dependencies between 
functional and non-functional score assignment is 
one of the directions of our future work. 
5 CONCLUSIONS 
In this paper, we have proposed an active testing 
based trust assessment approach. The approach can 
be applied to any entity of a telecommunication 
system; however, we preferred to draw our attention 
to the emerging concept of Systems as Services. 
In order to decide which input sequences can be 
included into a test suite under derivation, we 
proposed to use a machine learning approach. In this 
case, the machine that represents the prediction 
engine is built based on the training set provided by 
the experts. Later on, the machine allows to choose 
the test sequences that can potentially cause the 
system under test to produce untrustworthy outputs. 
To the best of our knowledge, it is the first proposal 
for using active testing techniques for SaS trust 
assessment, and the proposed approach brings a lot 
of challenges for the future work. In particular, we 
would like to perform experiments with the various 
SaS for estimating its validity and effectiveness. 
Later on, we would like to consider the test 
prioritization problem when the test sequences are 
being classified according to their abilities of setting 
the system to untrustworthy states. Finally, the 
active assessment of trustworthiness of an entity 
might be the first step in a trust certification process. 
Investigation of the applicability of the approach for 
the SaS trust certification is another challenge. 
The issues listed above form the nearest 
directions of the future work. 
ACKNOWLEDGEMENTS 
The work was partially supported by the Russian 
Science Foundation (RSF), project № 16-49-03012. 
REFERENCES 
Ardagna C.A., Asal R., Damiani E., Vu Q.H., 2015. From 
Security   to  Assurance  in  the  Cloud:  A  Survey.  In  
  ACM Computing Surveys , 48(1), pp. 1-50. 
Blum, A., Langley, P., 1997. Selection of Relevant 
IFeatures and Examples in Machine Learning. In 
Artificial Intelligence. V. 97, I. 1-2, pp. 245-271. 
Kushik, N., Yevtushenko, N., Evtushenko, T., 2016. 
Novel machine learning technique for predicting 
teaching strategy effectiveness. In International 
Journal of Information Management, DOI: 
10.1016/j.ijinfomgt.2016.02.006. 
López, J., Maag, S., 2015. Towards a Generic Trust 
Management Framework Using a Machine-Learning-
Based Trust Model. In IEEE Trustcom / BigDataSE / 
ISPA, Helsinki, pp. 1343-1348. doi: 
10.1109/Trustcom.2015.528. 
Lee, A.J., Winslett, M., Perano, K.J., 2009. TrustBuilder2: 
A Reconfigurable Framework for Trust Negotiation. 
In the IFIP International Conference on Trust 
Management. pp. 176-195. 
Blaze, M., Feigenbaum, J., Lacy, J., 1996. Decentralized 
Trust Management. In the IEEE Symposium on 
Security and Privacy. pp. 164-173. 
Jim, T., 2001. SD3: A Trust Management System with 
Certified Evaluation. In the IEEE Symposium on 
Security and Privacy. pp. 106-115. 
Chen, I., Guo, J., 2014. Dynamic Hierarchical Trust 
Management of Mobile Groups and Its Application to 
Misbehaving Node Detection. In the IEEE 
International Conference on Advanced Information 
Networking and Applications. pp. 49-56. 
López, J., Maag, S., Morales, G., 2016. Behavior 
evaluation for trust management based on formal 
distributed network monitoring. In World Wide Web 
V. 19, I. 1, pp. 21-39.  
Pautasso, C., Zimmermann, O., Leymann, F., 2008. 
Restful web services vs. “big”’ web services: making 
the right architectural decision. In the 17
th
 
international conference on World Wide Web. pp. 
805-814.  
Dabirsiaghi, A. 2016. Bypassing VBAAC with HTTP 
Verb Tampering: How to inadvertently allow hackers 
full access to your web application, Electronic 
resource:http://cdn2.hubspot.net/hub/315719/file-
1344244110-pdf/download-
files/Bypassing_VBAAC_with_HTTP_Verb_Tamperi
ng.pdf?t=1479325184680 (seen 01/12/2016). 
Boser, B.E., Guyon, I.M., Vapnik, V.N., 1992. A training 
algorithm for optimal margin classifiers. In the Fifth 
Annual Workshop on Computational Learning 
Theory. pp.144–152. 
Grandison, T., Sloman, M., 2003. Trust management tools 
for internet applications. In Trust Management, 
Springer First International Conference, iTrust, 
Heraklion, Crete, Greece. pp. 91–107. 
López, J., 2015. Distributed on-line network monitoring 
for trust assessment. Thesis of the University of Paris-
Saclay, France.