The Architectural Review of Web Security in Static and Dynamic Analysis

被引:0
|
作者
Wu, Raymond [1 ]
Hisada, Masayuki [1 ]
机构
[1] NST Inc, Dept Res & Dev, Aizu Wakamatsu, Fukushima, Japan
关键词
vulnerability; web security; validation; tracking; dominant; static analysis; dynamic analysis; automata;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Our objective in web security is to move black box to white box in enterprise practices. In this paper, we explain how our approaches achieve the goal in terms of static and dynamic analysis. To better explain the framework and roadmap of analysis work, we describe our approaches by using macro and micro views individually. Based on this foundation, we explore dynamic analysis in string validation and node tracking, and introduce micro and macro views to architect comprehensive approaches. Micro view is related to the mechanism inside the node, so the event triggers and string validation are both under its coverage. Macro view is related to the node tracking which is under investigation of pattern benchmarking. Our evaluation reflects that a configurable and well-tuned topology helps architectural collaboration, consequently it achieve a better security governance. This paper further explains the architectural coherence of identification, validation and tracking. It started with node identification with further exploration to the issue identification.
引用
收藏
页码:277 / 286
页数:10
相关论文
共 50 条
  • [1] Static and dynamic analysis for web security in industry applications
    Wu, Raymond
    Hisada, Masayuki
    [J]. INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2010, 3 (02) : 138 - 150
  • [2] Static and Dynamic Analysis for Web Security in Generic Format
    Wu, Raymond
    Hisada, Masayuki
    Ranaweera, Rasika
    [J]. GLOBAL SECURITY, SAFETY, AND SUSTAINABILITY, PROCEEDINGS, 2009, 45 : 233 - +
  • [3] Benchmarking Static Analysis Tools for Web Security
    Nunes, Paulo
    Medeiros, Iberia
    Fonseca, Jose C.
    Neves, Nuno
    Correia, Miguel
    Vieira, Marco
    [J]. IEEE TRANSACTIONS ON RELIABILITY, 2018, 67 (03) : 1159 - 1175
  • [4] Open Source Web Application Security: A Static Analysis Approach
    Alenezi, Mamdouh
    Javed, Yasir
    [J]. 2016 INTERNATIONAL CONFERENCE ON ENGINEERING & MIS (ICEMIS), 2016,
  • [5] On Combining Static, Dynamic and Interactive Analysis Security Testing Tools to Improve OWASP Top Ten Security Vulnerability Detection in Web Applications
    Mateo Tudela, Francesc
    Bermejo Higuera, Juan-Ramon
    Bermejo Higuera, Javier
    Sicilia Montalvo, Juan-Antonio
    Argyros, Michael I.
    [J]. APPLIED SCIENCES-BASEL, 2020, 10 (24): : 1 - 26
  • [6] Architectural Analysis for Security
    Ryoo, Jungwoo
    Kazman, Rick
    Anand, Priya
    [J]. IEEE SECURITY & PRIVACY, 2015, 13 (06) : 52 - 59
  • [7] On Combining Diverse Static Analysis Tools for Web Security: An Empirical Study
    Nunes, Paulo
    Medeiros, Iberia
    Fonseca, Jose
    Neves, Nuno
    Correia, Miguel
    Vieira, Marco
    [J]. 2017 13TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2017), 2017, : 121 - 128
  • [8] Combinatorial Method with Static Analysis for Source Code Security in Web Applications
    Higuera, Juan Ramon Bermejo
    Higuera, Javier Bermejo
    Montalvo, Juan Antonio Sicilia
    Riera, Tomas Sureda
    Argyros, Christopher I.
    Magrenan, A. Alberto
    [J]. CMES-COMPUTER MODELING IN ENGINEERING & SCIENCES, 2021, 129 (02): : 541 - 565
  • [9] A Research of On-Line Static Security Analysis Based On WEB Services
    Xu, Peng
    Liu, Wenying
    [J]. 2011 ASIA-PACIFIC POWER AND ENERGY ENGINEERING CONFERENCE (APPEEC), 2011,
  • [10] Static and dynamic semantics of the web
    Frye, C
    Plusch, M
    Lieberman, H
    [J]. SPINNING THE SEMANTIC WEB: BRINGING THE WORLD WIDE WEB TO ITS FULL POTENTIAL, 2003, : 377 - 401