Security Testing of Web Applications: A Research Plan

被引:0
|
作者
Avancini, Andrea [1 ]
机构
[1] Fdn Bruno Kessler, Trento, Italy
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cross-site scripting (XSS) vulnerabilities are specific flaws related to web applications, in which missing input validation can be exploited by attackers to inject malicious code into the application under attack. To guarantee high quality of web applications in terms of security, we propose a structured approach, inspired by software testing. In this paper we present our research plan and ongoing work to use security testing to address problems of potentially attackable code. Static analysis is used to reveal candidate vulnerabilities as a set of execution conditions that could lead to an attack. We then resort to automatic test case generation to obtain those input values that make the application execution satisfy such conditions. Eventually, we propose a security oracle to assess whether such test cases are instances of successful attacks.
引用
收藏
页码:1491 / 1494
页数:4
相关论文
共 50 条
  • [1] Security Testing Framework for Web Applications
    Alrawais, Layla Mohammed
    Alenezi, Mamdouh
    Akour, Mohammad
    [J]. INTERNATIONAL JOURNAL OF SOFTWARE INNOVATION, 2018, 6 (03) : 93 - 117
  • [2] Idea: Automatic Security Testing for Web Applications
    Dao, Thanh-Binh
    Shibayama, Etsuya
    [J]. ENGINEERING SECURE SOFTWARE AND SYSTEMS, PROCEEDINGS, 2009, 5429 : 180 - +
  • [3] Dual Security Testing Model for Web Applications
    Garima, Singh
    Manju, Kaushik
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (02) : 185 - 191
  • [4] Security testing of web applications: A systematic mapping of the literature
    Aydos, Murat
    Aldan, Cigdem
    Coskun, Evren
    Soydan, Alperen
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (09) : 6775 - 6792
  • [5] Software Security Testing of Web Applications Based on SSD
    Hui, Zhanwei
    Huang, Song
    [J]. ADVANCED INTELLIGENT COMPUTING THEORIES AND APPLICATIONS, 2010, 93 : 527 - 534
  • [6] Planning-based Security Testing of Web Applications
    Bozic, Josip
    Wotawa, Franz
    [J]. 2018 IEEE/ACM 13TH INTERNATIONAL WORKSHOP ON AUTOMATION OF SOFTWARE TEST (AST), 2018, : 20 - 26
  • [7] Ontology-driven Security Testing of Web Applications
    Bozic, Josip
    Li, Yihao
    Wotawa, Franz
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE TESTING (AITEST), 2020, : 115 - 122
  • [8] Automatic Model Inference of Web Applications for Security Testing
    Hossen, Karim
    Groz, Roland
    Oriat, Catherine
    Richier, Jean-Luc
    [J]. 2014 SEVENTH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION WORKSHOPS (ICSTW 2014), 2014, : 22 - 23
  • [9] Coverage Criteria for Automatic Security Testing of Web Applications
    Dao, Thanh Binh
    Shibayama, Etsuya
    [J]. INFORMATION SYSTEMS SECURITY, 2010, 6503 : 111 - +
  • [10] Security testing for web applications: A Systematic Literature Review
    Dominguez-Garcia, Antonio de Jesus
    Limon, Xavier
    Ocharan-Hernandez, Jorge Octavio
    Perez-Arriaga, Juan Carlos
    [J]. 2023 11TH INTERNATIONAL CONFERENCE IN SOFTWARE ENGINEERING RESEARCH AND INNOVATION, CONISOFT 2023, 2023, : 82 - 91