The Architectural Review of Web Security in Static and Dynamic Analysis

被引:0
|
作者
Wu, Raymond [1 ]
Hisada, Masayuki [1 ]
机构
[1] NST Inc, Dept Res & Dev, Aizu Wakamatsu, Fukushima, Japan
关键词
vulnerability; web security; validation; tracking; dominant; static analysis; dynamic analysis; automata;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Our objective in web security is to move black box to white box in enterprise practices. In this paper, we explain how our approaches achieve the goal in terms of static and dynamic analysis. To better explain the framework and roadmap of analysis work, we describe our approaches by using macro and micro views individually. Based on this foundation, we explore dynamic analysis in string validation and node tracking, and introduce micro and macro views to architect comprehensive approaches. Micro view is related to the mechanism inside the node, so the event triggers and string validation are both under its coverage. Macro view is related to the node tracking which is under investigation of pattern benchmarking. Our evaluation reflects that a configurable and well-tuned topology helps architectural collaboration, consequently it achieve a better security governance. This paper further explains the architectural coherence of identification, validation and tracking. It started with node identification with further exploration to the issue identification.
引用
收藏
页码:277 / 286
页数:10
相关论文
共 50 条
  • [41] A review of cyber security risks of power systems: from static to dynamic false data attacks
    Yan Xu
    [J]. Protection and Control of Modern Power Systems, 2020, 5
  • [42] Context-based Architectural Security Analysis
    Taspolatoglu, Emre
    Heinrich, Robert
    [J]. 2016 13TH WORKING IEEE/IFIP CONFERENCE ON SOFTWARE ARCHITECTURE (WICSA), 2016, : 281 - 282
  • [43] THE ANALYSIS OF THE SECURITY PROBLEM IN WEB
    Gao Wenju
    Ren Yueou
    Li Qiuju
    Wang Mingqian
    Li Zhe
    [J]. 2011 3RD INTERNATIONAL CONFERENCE ON COMPUTER TECHNOLOGY AND DEVELOPMENT (ICCTD 2011), VOL 1, 2012, : 37 - 41
  • [44] Analysis of Security on Web Site
    Li, Meihong
    Liu, Qiang
    Du, Ye
    Liu, Jidiang
    [J]. 2012 INTERNATIONAL CONFERENCE ON FUTURE COMMUNICATION AND COMPUTER TECHNOLOGY (ICFCCT 2012), 2012, : 121 - +
  • [45] Program Analysis for Web Security
    Mitchell, John C.
    [J]. STATIC ANALYSIS, 2011, 6887 : 4 - 4
  • [46] Architectural method to design and control dynamic composite web services
    Djenouhat, Manel Amel
    Belala, Faiza
    Barkaoui, Kamel
    [J]. INTERNATIONAL JOURNAL OF COMPUTER APPLICATIONS IN TECHNOLOGY, 2018, 57 (01) : 59 - 71
  • [47] Static security assessment of power systems: A review
    Gholami, Mostafa
    Sanjari, Mohammad J.
    Safari, Mostafa
    Akbari, Mahdi
    Kamali, Mohammadreza R.
    [J]. INTERNATIONAL TRANSACTIONS ON ELECTRICAL ENERGY SYSTEMS, 2020, 30 (09):
  • [48] Dynamic security labels and static information flow control
    Lantian Zheng
    Andrew C. Myers
    [J]. International Journal of Information Security, 2007, 6 : 67 - 84
  • [49] Static and Dynamic Informational Incentive Mechanisms for Security Enhancement
    Farhadi, Farzaneh
    Teneketzis, Demosthenis
    Golestani, S. Jamaloddin
    [J]. 2018 EUROPEAN CONTROL CONFERENCE (ECC), 2018, : 1042 - 1049
  • [50] Dynamic security labels and static information flow control
    Zheng, Lantian
    Myers, Andrew C.
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2007, 6 (2-3) : 67 - 84