首页> 外文会议>IEEE/IFIP International Conference on Dependable Systems Networks >Using web security scanners to detect vulnerabilities in web services
【24h】

Using web security scanners to detect vulnerabilities in web services

机译:使用Web安全扫描程序检测Web服务中的漏洞

获取原文

摘要

Although web services are becoming business-critical components, they are often deployed with critical software bugs that can be maliciously explored. Web vulnerability scanners allow detecting security vulnerabilities in web services by stressing the service from the point of view of an attacker. However, research and practice show that different scanners have different performance on vulnerabilities detection. In this paper we present an experimental evaluation of security vulnerabilities in 300 publicly available web services. Four well known vulnerability scanners have been used to identify security flaws in web services implementations. A large number of vulnerabilities has been observed, which confirms that many services are deployed without proper security testing. Additionally, the differences in the vulnerabilities detected and the high number of false-positives (35% and 40% in two cases) and low coverage (less than 20% for two of the scanners) observed highlight the limitations of web vulnerability scanners on detecting security vulnerabilities in web services.
机译:虽然Web服务正在成为业务关键组件,但它们通常会部署有可能恶意探索的关键软件错误。 Web漏洞扫描仪通过从攻击者的角度强调服务来允许通过强调服务来检测Web服务中的安全漏洞。但是,研究和实践表明,不同的扫描仪对漏洞检测具有不同的性能。在本文中,我们在300个公共网络服务中展示了安全漏洞的实验评估。已经使用了四个众所周知的漏洞扫描仪来识别Web服务实现中的安全漏洞。已经观察到大量漏洞,这证实了在没有适当的安全测试的情况下部署许多服务。此外,检测到漏洞的差异和误报的差异(两种情况下为35%和40%)和低覆盖率(两个扫描仪的低于20%),观察到突出显示Web漏洞扫描仪对检测的限制Web服务中的安全漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号