Interactive Application Security Testing

被引:11
|
作者
Yuan YuanPan [1 ]
机构
[1] Anhui Ist Int Business, Dept Commerce & Trade Circulat, Hefei 230000, Anhui, Peoples R China
关键词
IAST; SAST; DAST; Information security;
D O I
10.1109/ICSGEA.2019.00131
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The operation of e-commerce platform requires very high security. Interactive Application Security Test (IAST) is a new generation of vulnerability analysis technology first proposed by Synopsys Company in the United States. This technology can effectively solve the technical vulnerabilities of various websites represented by e-commerce platform. This technology combines static application security test (SAST) with dynamic application security test (DAST) by using a unique design context context association mechanism. Through this deep integration of interaction capabilities and differential comparison mechanism, a fast and highly automated vulnerability analysis capability can be built in miming applications. IAST integrates the advantages of SAST and DAST technology, continuously monitors and identifies vulnerabilities in applications. Aspect-oriented programming technology enables differential comparison mechanism to perform dynamic security analysis in running programs, and extracts contextual content, data flow and flow control information from active applications to provide targeted information. Run the access capability of the actual data values at the code level. Therefore, precisely because of these abundant information, the differential comparison mechanism can identify more anomalies than other existing security tools, and achieve unprecedented accuracy. Through IAST technology, it can also confirm or eliminate whether the detected vulnerabilities can be used to attack, and determine the location of the vulnerabilities in the application code. This technology has been listed as one of the top ten information security technologies in 2014 by Gartner Information Technology Research and Consulting Company of the United States, and has a very broad application prospects.
引用
收藏
页码:558 / 561
页数:4
相关论文
共 50 条
  • [1] Testing Application Security with Aspects
    Jain, Manish
    Gopalani, Dinesh
    2016 INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, AND OPTIMIZATION TECHNIQUES (ICEEOT), 2016, : 3161 - 3165
  • [2] Application of interactive technology for training in the security area
    Valerio Netto, Antonio
    2015 XVII SYMPOSIUM ON VIRTUAL AND AUGMENTED REALITY, 2015, : 127 - 132
  • [3] ITERATIVE USABILITY TESTING OF A SECURITY APPLICATION
    KARAT, CM
    PROCEEDINGS OF THE HUMAN FACTORS SOCIETY 33RD ANNUAL MEETING, VOL 1: PERSPECTIVES, 1989, : 273 - 280
  • [4] Indoor environment modeling for interactive robot security application
    Jo, Sangwoo
    Shahab, Qonita M.
    Kwon, Yong-Moo
    Ahn, Sang Chul
    INTELLIGENT ROBOTS AND COMPUTER VISION XXIV: ALGORITHMS, TECHNIQUES, AND ACTIVE VISION, 2006, 6384
  • [5] Red-team application security testing - Testing techniques designed to expose security bugs
    Thompson, HH
    Chase, SG
    DR DOBBS JOURNAL, 2003, 28 (11): : 18 - +
  • [6] A Database Security Testing Scheme of Web Application
    Yang Haixia
    Nan Zhihong
    ICCSSE 2009: PROCEEDINGS OF 2009 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE & EDUCATION, 2009, : 953 - +
  • [7] Strict Conformance Testing for TCP application security
    Jin, H.
    Wang, Y. L.
    Gao, H. Y.
    Chen, N. W.
    2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES: ITESS 2008, VOL 2, 2008, : 621 - 625
  • [8] A testing framework for Web application security assessment
    Huang, YW
    Tsai, CH
    Lin, TP
    Huang, SK
    Lee, DT
    Kuo, SY
    COMPUTER NETWORKS, 2005, 48 (05) : 739 - 761
  • [9] The Application of Software Testing Technology on Security in Web Application System
    Zhai, Hui
    Shi, Hui
    Zhai, Rui
    MECHATRONICS ENGINEERING, COMPUTING AND INFORMATION TECHNOLOGY, 2014, 556-562 : 6159 - 6161
  • [10] TTTEST: The Tool Support for Testing Interactive Multimodal Application
    Le Thanh Long
    Nguyen Thanh Binh
    Parissis, Ioannis
    2016 INTERNATIONAL CONFERENCE ON ELECTRONICS, INFORMATION, AND COMMUNICATIONS (ICEIC), 2016,