首页> 外文会议>International Workshop on Automation of Software Test >Grammar based oracle for security testing of web applications
【24h】

Grammar based oracle for security testing of web applications

机译:基于语法的Web应用程序安全测试的Oracle

获取原文

摘要

The goal of security testing is to detect those defects that could be exploited to conduct attacks. Existing works, however, address security testing mostly from the point of view of automatic generation of test cases. Less attention is paid to the problem of developing and integrating with a security oracle. In this paper we address the problem of the security oracle, in particular for Cross-Site Scripting vulnerabilities. We rely on existing test cases to collect HTML pages in safe conditions, i.e. when no attack is run. Pages are then used to construct the safe model of the application under analysis, a model that describes the structure of an application response page for safe input values. The oracle eventually detects a successful attack when a test makes the application display a web page that is not compliant with the safe model.
机译:安全测试的目标是检测可能被剥削进行攻击的那些缺陷。 然而,现有的作品主要从自动生成测试用例的角度来解决安全测试。 对与安全甲骨文发展和整合的问题缩短关注。 在本文中,我们解决了安全oracle的问题,特别是对于跨站点脚本漏洞。 我们依靠现有的测试用例来在安全条件下收集HTML页面,即,当没有攻击时。 然后使用页面来构建在分析下的应用程序的安全模型,该模型描述了用于安全输入值的应用程序响应页面的结构。 Oracle最终检测到测试时的成功攻击使应用程序显示不符合安全模型的网页。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号