首页> 外文会议>International Conference on Network-Based Information Systems >A New Security Testing Method for Detecting Flash Vulnerabilities by Generating Test Patterns
【24h】

A New Security Testing Method for Detecting Flash Vulnerabilities by Generating Test Patterns

机译:一种通过生成测试模式来检测Flash漏洞的新安全测试方法

获取原文

摘要

Flash has a number of security defects even though Flash Player is installed on most of world’s PC. Protection using sandbox has limitation to protect a user from vulnerabilities of Flash application because an attacker can attack a vulnerable Flash application when a sandbox can’t work if an engineer or a web administrator set sandbox permission wrongly. Another way to solve it is testing. As a testing, penetration testing is useful for detecting vulnerability of Flash Application. Existing penetration testing performs penetration test through UI manually, which is inefficient and time consuming. In this paper, to overcome a problem of existing penetration test, we design a new penetration testing, which enables to generate as many test patterns as possible from VM inputs, inputting test patterns into VM, and checks the existence of vulnerabilities from VM outputs automatically. We demonstrate our testing method using an example, which can detect Flash Parameter Injection that is a one kind of vulnerability of Flash application.
机译:即使在世界上大多数PC上安装Flash Player,Flash也有许多安全缺陷。使用Sandbox的保护具有限制,可以保护用户免受Flash应用程序的漏洞,因为如果攻击者在Sandbox如果工程师或Web管理员设置Sandbox权限错误时攻击易受攻击的Flash应用程序。错误地错误。另一种解决它正在测试的方法。作为测试,渗透测试可用于检测闪光应用的脆弱性。现有的渗透测试手动通过UI进行穿透测试,这是效率低下且耗时的。在本文中,为了克服现有渗透测试的问题,我们设计了一种新的渗透测试,它能够从VM输入开始产生尽可能多的测试模式,将测试模式输入VM,并自动检查VM输出的漏洞的存在。我们使用示例演示了我们的测试方法,可以检测Flash参数注入,这是一种闪光应用的一种漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号