首页> 外文会议>Saudi Computer Society National Computer Conference >Website security analysis: variation of detection methods and decisions
【24h】

Website security analysis: variation of detection methods and decisions

机译:网站安全分析:检测方法和决策的变化

获取原文

摘要

Websites and web applications continue to evolve in terms of how they are developed and used. Different types of components in those websites and applications communicate with users through inputs taken from the users and outputs displayed to those users. Users, intentionally or unintentionally, may provide improper inputs. We proposed a model to investigate the behavior of websites when dealing with invalid inputs. From security perspectives, invalid inputs should be detected and rejected as early as possible. An invalid input is considered as a form of successful attack if it is processed by the website code or back-end database. Based on this assumption, we proposed a list of indicators that test invalid inputs are processed. A tool is developed to implement this model. We tested the model through evaluating several websites selected randomly. Our tool has no special credentials or access to any of the tested websites. We found many SQL injection vulnerabilities based on our proposed model. Upon the manual investigation of the web pages that showed such vulnerabilities, we found few instances of false positives. We believe that this can provide a systematic and automated approach to test websites for vulnerabilities related to improper input validation.
机译:网站和Web应用程序在开发和使用方式方面不断发展。这些网站和应用程序中不同类型的组件通过从用户获取的输入和显示给这些用户的输出与用户进行通信。用户有意或无意地提供了不正确的输入。我们提出了一个模型来调查网站在处理无效输入时的行为。从安全的角度来看,应该尽早发现无效输入并予以拒绝。如果无效输入由网站代码或后端数据库处理,则被视为成功攻击的一种形式。基于此假设,我们提出了一系列测试无效输入的指标。开发了一种工具来实现此模型。我们通过评估随机选择的几个网站来测试该模型。我们的工具没有特殊的凭据或访问任何经过测试的网站。我们基于提出的模型发现了许多SQL注入漏洞。在对显示出此类漏洞的网页进行的手动调查中,我们发现了很少的误报实例。我们认为,这可以为测试网站提供与输入验证不当相关的漏洞的系统,自动化的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号