跳至主導覽 跳至搜尋 跳過主要內容

A testing framework for Web application security assessment

  • Yao Wen Huang*
  • , Chung Hung Tsai
  • , Tsung Po Lin
  • , Shih Kun Huang
  • , D. T. Lee
  • , Sy Yen Kuo
  • *此作品的通信作者
  • National Taiwan University
  • Academia Sinica - Institute of Information Science
  • National Yang Ming Chiao Tung University

研究成果: 期刊稿件文章同行評審

59 引文 斯高帕斯(Scopus)

摘要

The rapid development phases and extremely short turnaround time of Web applications make it difficult to eliminate their vulnerabilities. Here we study how software testing techniques such as fault injection and runtime monitoring can be applied to Web applications. We implemented our proposed mechanisms in the Web Application Vulnerability and Error Scanner (WAVES)-a black-box testing framework for automated Web application security assessment. Real-world situations are used to test WAVES and to compare it with other tools. Our results show that WAVES is a feasible platform for assessing Web application security.

原文英語
頁(從 - 到)739-761
頁數23
期刊Computer Networks
48
發行號5
DOIs
出版狀態已出版 - 05 08 2005
對外發佈

指紋

深入研究「A testing framework for Web application security assessment」主題。共同形成了獨特的指紋。

引用此