A Threat Model-Driven Security Testing Approach for Web Application

被引:0
|
作者
Yan, Bobo [1 ]
Li, Xiaohong [1 ]
Du, Zhijie [1 ]
机构
[1] TianJin Univ Tianjin, Tianjin Univ, Coll Software, Tianjin, Peoples R China
关键词
Web application; Security testing; Threat Modeling; Attack pattern;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Web applications have been playing a more and more essential role in daily life; hence, the problem of security is gaining more focus, and consequently a great deal of research on web application security testing has been developed. Among them, however, the most have been concentrated on the testing procedure arranged after the completion of the implementation process. In this paper, we propose a threat model-driven security testing approach for detecting threats, which consists of four activities: building threat tree, according to the attack pattern, against the threats web applications may confront; deriving a security testing sequence from thread model; deriving security testing data from UML sequence diagram parameters for extracting test inputs; generating executable security test case. Also, we proposed an algorithm for generating security testing sequences and conducted an empirical study to show the feasibility and effectiveness of our approach.
引用
收藏
页码:158 / 168
页数:11
相关论文
共 50 条
  • [1] A framework of model-driven web application testing
    Li, Nuo
    Ma, Qin-qin
    Wu, Ji
    Jin, Mao-zhong
    Liu, Chao
    [J]. 30TH ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE, VOL 2, SHORT PAPERS/WORKSHOPS/FAST ABSTRACTS/DOCTORAL SYMPOSIUM, PROCEEDINGS, 2006, : 157 - 162
  • [2] Towards model-driven testing of a Web application generator
    Baresi, L
    Fraternali, P
    Tisi, M
    Morasca, S
    [J]. WEB ENGINEERING, PROCEEDINGS, 2005, 3579 : 75 - 86
  • [3] A Model-Driven Approach to Web Applications
    Kozlovics, Sergejs
    [J]. DATABASES AND INFORMATION SYSTEMS IX, 2016, 291 : 73 - 86
  • [4] Model-driven security based on a Web services security architecture
    Nakamura, Y
    Tatsubori, M
    Imamura, T
    Ono, K
    [J]. 2005 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, VOL 1, PROCEEDINGS, 2005, : 7 - 15
  • [5] A Methodology for Model-Driven Web Application Composition
    Kateros, Dimitrios A.
    Kapitsaki, Georgia M.
    Tselikas, Nikolaos D.
    Venieris, Iakovos S.
    [J]. 2008 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, VOL 2, 2008, : 489 - 492
  • [6] A Model-Driven approach to Information Security Compliance
    Correia, Anacleto
    Goncalves, Antonio
    Filomena Teodoro, M.
    [J]. APPLIED MATHEMATICS AND COMPUTER SCIENCE, 2017, 1836
  • [7] Recommender Systems on the Web: A Model-Driven Approach
    Rojas, Gonzalo
    Dominguez, Francisco
    Salvatori, Stefano
    [J]. E-COMMERCE AND WEB TECHNOLOGIES, PROCEEDINGS, 2009, 5692 : 252 - 263
  • [8] A model-driven approach of Web Services development
    Li, Jia
    Zhang, Heming
    [J]. DCABES 2006 Proceedings, Vols 1 and 2, 2006, : 1102 - 1106
  • [9] A Reflective Approach to Model-Driven Web Engineering
    Clowes, Darren
    Kolovos, Dimitris
    Holmes, Chris
    Rose, Louis
    Paige, Richard
    Johnson, Julian
    Dawson, Ray
    Probets, Steve
    [J]. MODELLING FOUNDATIONS AND APPLICATIONS, PROCEEDINGS, 2010, 6138 : 62 - +
  • [10] Integration and Exchangeability of External Security-Critical Web Services in a Model-Driven Approach
    Borek, Marian
    Stenzel, Kurt
    Katkalov, Kuzman
    Reif, Wolfgang
    [J]. ADVANCES IN CONCEPTUAL MODELING, ER 2015 WORKSHOPS, 2015, 9382 : 63 - 73