Pattern based Web Security Testing

被引:0
|
作者
Araujo, Paulo J. M. [1 ]
Paiva, Ana C. R. [1 ,2 ]
机构
[1] Univ Porto, Fac Engn, Rua Dr Roberto Frias S-N, P-4200465 Porto, Portugal
[2] INESC TEC, Rua Dr Roberto Frias S-N, P-4200465 Porto, Portugal
关键词
Security Testing; Pattern based Testing; Pattern based Security Testing; Security Web Testing;
D O I
10.5220/0006606504720479
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a Pattern Based Testing approach for testing security aspects of the applications under test (AUT). It describes the two security patterns which are the focus of this work ("Account Lockout" and "Authentication Enforcer") and the test strategies implemented to check if the applications are vulnerable or not regarding these patterns. The PBST (Pattern Based Security Testing) overall approach has two phases: exploration (to identify the web pages of the application under test) and testing (to execute the test strategies developed in order to detect vulnerabilities). An experiment is presented to validate the approach over five public web applications. The goal is to assess the behavior of the tool when varying the upper limit of pages to visit and assess its capacity to find real vulnerabilities. The results are promising. Indeed, it was possible to check that the vulnerabilities detected corresponded to real security problems.
引用
下载
收藏
页码:472 / 479
页数:8
相关论文
共 50 条
  • [31] SMRL: A Metamorphic Security Testing Tool for Web Systems
    Mai, Phu X.
    Goknil, Arda
    Pastore, Fabrizio
    Briand, Lionel C.
    2020 ACM/IEEE 42ND INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS (ICSE-COMPANION 2020), 2020, : 9 - 12
  • [32] Collaborative Security Annotation and Online Testing for Web APIs
    Chen, Hsiao-Jung
    Ma, Shang-Pin
    Lu, Hsueh-Cheng
    2021 IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE 2021), 2021, : 9 - 15
  • [33] Web App Security A Comparison and Categorization of Testing Frameworks
    Srinivasan, Satish M.
    Sangwan, Raghvinder S.
    IEEE SOFTWARE, 2017, 34 (01) : 99 - 102
  • [34] Security testing of web applications: A systematic mapping of the literature
    Aydos, Murat
    Aldan, Cigdem
    Coskun, Evren
    Soydan, Alperen
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (09) : 6775 - 6792
  • [35] Automatic Model Inference of Web Applications for Security Testing
    Hossen, Karim
    Groz, Roland
    Oriat, Catherine
    Richier, Jean-Luc
    2014 SEVENTH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION WORKSHOPS (ICSTW 2014), 2014, : 22 - 23
  • [36] Ontology-driven Security Testing of Web Applications
    Bozic, Josip
    Li, Yihao
    Wotawa, Franz
    2020 IEEE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE TESTING (AITEST), 2020, : 115 - 122
  • [37] Coverage Criteria for Automatic Security Testing of Web Applications
    Dao, Thanh Binh
    Shibayama, Etsuya
    INFORMATION SYSTEMS SECURITY, 2010, 6503 : 111 - +
  • [38] Using mobile agents for security testing in web environments
    Chang, WK
    Chuang, MH
    Yang, CT
    SOFTWARE QUALITY - ECSQ 2002, 2002, 2349 : 42 - 52
  • [39] Vulnerability Coverage Criteria for Security Testing of Web Applications
    Murthy, P. V. R.
    Shilpa, R. G.
    2018 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2018, : 489 - 494
  • [40] Security testing for web applications: A Systematic Literature Review
    Dominguez-Garcia, Antonio de Jesus
    Limon, Xavier
    Ocharan-Hernandez, Jorge Octavio
    Perez-Arriaga, Juan Carlos
    2023 11TH INTERNATIONAL CONFERENCE IN SOFTWARE ENGINEERING RESEARCH AND INNOVATION, CONISOFT 2023, 2023, : 82 - 91