首页> 外文会议>International Workshop on Automation of Software Test >XSS Pattern for Attack Modeling in Testing
【24h】

XSS Pattern for Attack Modeling in Testing

机译:用于测试中攻击建模的XSS模式

获取原文

摘要

Security issues of web applications are still a current topic of interest especially when considering the consequences of unintended behaviour. Such services might handle sensitive data about several thousands or millions of users. Hence, exploiting services or other undesired effects that cause harm on users has to be avoided. Therefore, for software developers of such applications one of the major tasks in providing security is to embed testing methodologies into the software development cycle, thus minimizing the subsequent damage resulting in debugging and time intensive upgrading. Model-based testing evolved as one of the methodologies which offer several theoretical and practical approaches in testing the system under test (SUT) that combine several input generation strategies like mutation testing, using of concrete and symbolic execution etc. by putting the emphasis on specification of the model of an application. In this work we propose an approach that makes use of an attack pattern model in form of a UML state machine for test case generation and execution. The paper also discusses the current implementation of our attack pattern testing tool using a XSS attack pattern and demonstrates the execution in a case study.
机译:Web应用程序的安全问题仍然是当前感兴趣的主题,特别是在考虑意外行为的后果时。此类服务可能会处理大约数千或数百万用户的敏感数据。因此,必须避免对造成对用户造成伤害的服务或其他不良影响。因此,对于这些应用程序的软件开发人员提供安全性的主要任务之一是将测试方法嵌入到软件开发周期中,从而最大限度地减少随后的损坏导致调试和时间升级。基于模型的测试演变为一种方法,它提供了在测试系统(SUT)的测试中提供了几种理论和实用方法,该方法将多种输入生成策略如突变测试,混凝土和符号执行等所在的突变测试相结合,通过强调规范应用程序的模型。在这项工作中,我们提出了一种方法,该方法是以UML状态机的形式使用攻击模式模型,以进行测试用例生成和执行。本文还讨论了使用XSS攻击模式的攻击模式测试工具的当前实施,并在案例研究中演示执行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号