Involves data perturbation (i.e., alteration of the type of data the execution environment components pass to the application, or that the application’s components pass to one another). Fault injection can reveal the effects of security defects on the behavior of the components themselves and on the application as a whole.
Source(s):
NIST SP 800-95
from
Software Assurance in Acquisition: Mitigating Risks to the Enterprise