首页> 外文会议>IEEE International Conference on Advanced Information Networking and Applications >Towards Continuous Security Certification of Software-as-a-Service Applications Using Web Application Testing Techniques
【24h】

Towards Continuous Security Certification of Software-as-a-Service Applications Using Web Application Testing Techniques

机译:使用Web应用程序测试技术实现软件即服务应用程序的连续安全认证

获取原文

摘要

Continuous security certification of software-as-a-service (SaaS) aims at continuously, i.e. repeatedly and automatically validating whether a SaaS application adheres to a set of security requirements. Since SaaS applications make heavy use of web application technologies, checking security requirements with the help of web application testing techniques seems evident. However, these techniques mainly focus on conducting discrete security tests, that is, mostly manually triggered tests whose results are interpreted by human experts. Thus these techniques are not per se suited to support continuous security certification of SaaS applications and have to be adapted accordingly. In this paper, we report on our current status of developing methods and tools to support test-based, continuous security certification of SaaS applications which make use of web application testing techniques. To that end, we describe major challenges to overcome and present experimental test results of using SQLMap to continuously test for SQL injection vulnerabilities.
机译:软件即服务(SaaS)的连续安全性认证旨在连续地,即反复并自动地验证SaaS应用程序是否符合一组安全性要求。由于SaaS应用程序大量使用Web应用程序技术,因此在Web应用程序测试技术的帮助下检查安全性需求似乎很明显。但是,这些技术主要集中于进行离散的安全测试,即大多数手动触发的测试,其结果由人类专家解释。因此,这些技术本身并不适合支持SaaS应用程序的连续安全性认证,因此必须进行相应的调整。在本文中,我们报告了我们开发方法和工具的当前状态,这些方法和工具可支持使用Web应用程序测试技术的基于测试的SaaS应用程序的连续安全认证。为此,我们描述了要克服的主要挑战,并提供了使用SQLMap连续测试SQL注入漏洞的实验测试结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号