Security Testing of Web Applications: A Research Plan

被引:0
|
作者
Avancini, Andrea [1 ]
机构
[1] Fdn Bruno Kessler, Trento, Italy
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cross-site scripting (XSS) vulnerabilities are specific flaws related to web applications, in which missing input validation can be exploited by attackers to inject malicious code into the application under attack. To guarantee high quality of web applications in terms of security, we propose a structured approach, inspired by software testing. In this paper we present our research plan and ongoing work to use security testing to address problems of potentially attackable code. Static analysis is used to reveal candidate vulnerabilities as a set of execution conditions that could lead to an attack. We then resort to automatic test case generation to obtain those input values that make the application execution satisfy such conditions. Eventually, we propose a security oracle to assess whether such test cases are instances of successful attacks.
引用
收藏
页码:1491 / 1494
页数:4
相关论文
共 50 条
  • [31] Pattern based Web Security Testing
    Araujo, Paulo J. M.
    Paiva, Ana C. R.
    [J]. PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON MODEL-DRIVEN ENGINEERING AND SOFTWARE DEVELOPMENT, 2018, : 472 - 479
  • [32] Metamorphic Security Testing for Web Systems
    Mai, Phu X.
    Pastore, Fabrizio
    Goknil, Arda
    Briand, Lionel
    [J]. 2020 IEEE 13TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VALIDATION AND VERIFICATION (ICST 2020), 2020, : 186 - 197
  • [33] Metamorphic Testing for Web System Security
    Chaleshtari, Nazanin Bayati
    Pastore, Fabrizio
    Goknil, Arda
    Briand, Lionel C.
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2023, 49 (06) : 3430 - 3471
  • [34] Research Questions for Model-Based Vulnerability Testing of Web Applications
    Vernotte, Alexandre
    [J]. 2013 IEEE SIXTH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST 2013), 2013, : 505 - 506
  • [35] Statistical testing of Web applications
    Tonella, P
    Ricca, F
    [J]. JOURNAL OF SOFTWARE MAINTENANCE AND EVOLUTION-RESEARCH AND PRACTICE, 2004, 16 (1-2): : 103 - 127
  • [36] Analysis and testing of Web applications
    Ricca, F
    Tonella, P
    [J]. PROCEEDINGS OF THE 23RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, 2001, : 25 - 34
  • [37] Pen Testing for Web Applications
    Al-Ahmad, Ahmad
    Abu Ata, Belal
    Wahbeh, Abdullah H. S.
    [J]. INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY AND WEB ENGINEERING, 2012, 7 (03) : 1 - 13
  • [38] A framework for Web applications testing
    Xu, L
    Xu, BW
    [J]. 2004 INTERNATIONAL CONFERENCE ON CYBERWORLDS, PROCEEDINGS, 2004, : 300 - 305
  • [39] Progress in testing for web applications
    Deng, Xiaopeng
    Xing, Chunxiao
    Cai, Lianhong
    [J]. Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2007, 44 (08): : 1273 - 1283
  • [40] Structural testing of Web applications
    Liu, CH
    Kung, DC
    Hsia, P
    Hsu, CT
    [J]. 11TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, PROCEEDINGS, 2000, : 84 - 96