首页> 外文会议>IEEE/ACM International Workshop on Automation of Software Test >Planning-Based Security Testing of Web Applications
【24h】

Planning-Based Security Testing of Web Applications

机译:Web应用程序的规划安全测试

获取原文

摘要

Web applications are deployed on machines around the globe and offer almost universal accessibility. The systems ensure functional interconnectivity between different components on a 24/7 basis. One of the most important requirements represents data confidentiality and secure authentication. However, implementation flaws and unfulfilled requirements can result in security leaks that can be eventually exploited by a malicious user. Here different testing methods are applied in order to detect software defects and prevent unauthorized access in advance. Automated planning and scheduling provides the possibility to specify a specific problem and to generate plans, which in turn guide the execution of a program. In this paper, a planning-based approach is introduced for modeling and testing of web applications. The specification offers a high degree of extendibility and configurability but overcomes the limits of traditional graphical representations as well. In this way, new testing possibilities emerge that eventually lead to better vulnerability detection, thereby ensuring more secure services.
机译:Web应用程序部署在全球的机器上,并提供几乎通用的可访问性。该系统在24/7的基础上确保不同组件之间的功能互连。最重要的要求之一代表数据机密性和安全身份验证。但是,实施缺陷和未实现的要求可能导致安全泄漏,这些泄漏可能最终被恶意用户利用。这里应用不同的测试方法,以便检测软件缺陷并预防未经授权的访问。自动规划和调度提供了指定特定问题并生成计划的可能性,从而指导程序的执行。本文介绍了一种用于对Web应用的建模和测试的规划方法。该规范提供了高度的可扩展性和可配置性,但也克服了传统图形表示的极限。通过这种方式,新的测试可能出现,最终导致更好的漏洞检测,从而确保了更安全的服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号