首页> 外文会议>The 2nd International Conference on Information Science and Engineering >Research on mock attack testing for SQL injection vulnerability in multi-defense level web applications
【24h】

Research on mock attack testing for SQL injection vulnerability in multi-defense level web applications

机译:多防御级别Web应用程序中针对SQL注入漏洞的模拟攻击测试研究

获取原文

摘要

The testing methods for hunting vulnerabilities in web applications can be mainly classified into two categories: white box testing and black box testing. This paper focuses on the research on black box testing for the SQL injection vulnerability. Through the combination of fuzzy test and mock attack testing, a new testing method for hunting SQL injection is proposed, in which the injection parameters can be divided into several sets of equivalence classes according to the defined multi-defense levels of testee web systems. By injecting the most representative parameters selected from each equivalence classes, the mock attack testing for hunting SQL injection can be very effective and low cost. Experimental result shows that this method can achieve desirable result for SQLI mock attack testing in real web applications.
机译:用于检测Web应用程序中漏洞的测试方法主要可以分为两类:白盒测试和黑盒测试。本文重点研究针对SQL注入漏洞的黑盒测试。通过将模糊测试和模拟攻击测试相结合,提出了一种新的SQL注入测试方法,根据定义的测试对象Web系统的多防御级别,可以将注入参数分为几组等效类。通过注入从每个等效类中选择的最具代表性的参数,用于搜寻SQL注入的模拟攻击测试可以非常有效且成本低廉。实验结果表明,该方法可以在实际的Web应用程序中实现SQLI模拟攻击测试的理想结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号