Pattern based Web Security Testing

被引:0
|
作者
Araujo, Paulo J. M. [1 ]
Paiva, Ana C. R. [1 ,2 ]
机构
[1] Univ Porto, Fac Engn, Rua Dr Roberto Frias S-N, P-4200465 Porto, Portugal
[2] INESC TEC, Rua Dr Roberto Frias S-N, P-4200465 Porto, Portugal
关键词
Security Testing; Pattern based Testing; Pattern based Security Testing; Security Web Testing;
D O I
10.5220/0006606504720479
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a Pattern Based Testing approach for testing security aspects of the applications under test (AUT). It describes the two security patterns which are the focus of this work ("Account Lockout" and "Authentication Enforcer") and the test strategies implemented to check if the applications are vulnerable or not regarding these patterns. The PBST (Pattern Based Security Testing) overall approach has two phases: exploration (to identify the web pages of the application under test) and testing (to execute the test strategies developed in order to detect vulnerabilities). An experiment is presented to validate the approach over five public web applications. The goal is to assess the behavior of the tool when varying the upper limit of pages to visit and assess its capacity to find real vulnerabilities. The results are promising. Indeed, it was possible to check that the vulnerabilities detected corresponded to real security problems.
引用
下载
收藏
页码:472 / 479
页数:8
相关论文
共 50 条
  • [1] Attack Pattern-Based Combinatorial Testing with Constraints for Web Security Testing
    Bozic, Josip
    Garn, Bernhard
    Kapsalis, Ioannis
    Simos, Dimitris E.
    Winkler, Severin
    Wotawa, Franz
    2015 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITY (QRS 2015), 2015, : 207 - 212
  • [2] Software Security Testing of Web Applications Based on SSD
    Hui, Zhanwei
    Huang, Song
    ADVANCED INTELLIGENT COMPUTING THEORIES AND APPLICATIONS, 2010, 93 : 527 - 534
  • [3] Planning-based Security Testing of Web Applications
    Bozic, Josip
    Wotawa, Franz
    2018 IEEE/ACM 13TH INTERNATIONAL WORKSHOP ON AUTOMATION OF SOFTWARE TEST (AST), 2018, : 20 - 26
  • [4] A randomized method of information security testing based on adversary pattern
    He, Hong
    Yuan, Sheng-Zhong
    ADVANCING SCIENCE THROUGH COMPUTATION, 2008, : 291 - 294
  • [5] A pattern for WSDL-Based Testing of Web Service Compositions
    Petrova-Antonova, Dessislava
    Ilieva, Sylvia
    Stoyanova, Vera
    PROCEEDINGS OF THE 20TH EUROPEAN CONFERENCE ON PATTERN LANGUAGES OF PROGRAMS (EUROPLOP 2015), 2015,
  • [6] Web Sites Information Security Management Based on B/S Pattern
    Zhu, Xiaolong
    INFORMATION TECHNOLOGY APPLICATIONS IN INDUSTRY, PTS 1-4, 2013, 263-266 : 3141 - 3144
  • [7] Security Testing Framework for Web Applications
    Alrawais, Layla Mohammed
    Alenezi, Mamdouh
    Akour, Mohammad
    INTERNATIONAL JOURNAL OF SOFTWARE INNOVATION, 2018, 6 (03) : 93 - 117
  • [8] Metamorphic Security Testing for Web Systems
    Mai, Phu X.
    Pastore, Fabrizio
    Goknil, Arda
    Briand, Lionel
    2020 IEEE 13TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VALIDATION AND VERIFICATION (ICST 2020), 2020, : 186 - 197
  • [9] Metamorphic Testing for Web System Security
    Chaleshtari, Nazanin Bayati
    Pastore, Fabrizio
    Goknil, Arda
    Briand, Lionel C.
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2023, 49 (06) : 3430 - 3471
  • [10] Knowledge-based security testing of web applications by logic programming
    Zech, Philipp
    Felderer, Michael
    Breu, Ruth
    INTERNATIONAL JOURNAL ON SOFTWARE TOOLS FOR TECHNOLOGY TRANSFER, 2019, 21 (02) : 221 - 246