Skip to main navigation Skip to search Skip to main content

A testing framework for Web application security assessment

  • Yao Wen Huang*
  • , Chung Hung Tsai
  • , Tsung Po Lin
  • , Shih Kun Huang
  • , D. T. Lee
  • , Sy Yen Kuo
  • *Corresponding author for this work
  • National Taiwan University
  • Academia Sinica - Institute of Information Science
  • National Yang Ming Chiao Tung University

Research output: Contribution to journalJournal Article peer-review

59 Scopus citations

Abstract

The rapid development phases and extremely short turnaround time of Web applications make it difficult to eliminate their vulnerabilities. Here we study how software testing techniques such as fault injection and runtime monitoring can be applied to Web applications. We implemented our proposed mechanisms in the Web Application Vulnerability and Error Scanner (WAVES)-a black-box testing framework for automated Web application security assessment. Real-world situations are used to test WAVES and to compare it with other tools. Our results show that WAVES is a feasible platform for assessing Web application security.

Original languageEnglish
Pages (from-to)739-761
Number of pages23
JournalComputer Networks
Volume48
Issue number5
DOIs
StatePublished - 05 08 2005
Externally publishedYes

Keywords

  • Black-box testing
  • Complete crawling
  • Fault injection
  • Security assessment
  • Web application testing

Fingerprint

Dive into the research topics of 'A testing framework for Web application security assessment'. Together they form a unique fingerprint.

Cite this