首页> 外文期刊>Computing reviews >Security testing methodology for vulnerabilities detection of XSS in web services and WS-Security
【24h】

Security testing methodology for vulnerabilities detection of XSS in web services and WS-Security

机译:用于Web服务和WS-Security中XSS漏洞检测的安全测试方法

获取原文
获取原文并翻译 | 示例
           

摘要

Websites, like most other software components, are vulnerable to attacks. Cross-site scripting (XSS) attacks are a type of malicious code injection in which malicious scripts are injected into websites. Currently, many websites are used to execute software components called web services. In my opinion, web services can be considered the most important components to integrate different software technologies. Web services security, defined in the Web Services Security (WS-Security) standard, is important for analyzing XSS attacks. In this paper, the authors analyze the robustness of web services using security testing techniques. This is a very practical paper. The authors describe in detail how to test vulnerabilities in web services, and how to discover new vulnerabilities during software development before attackers exploit them. The paper shows how certain tools can be used to analyze the presence of vulnerabilities in web services and emulate an XSS attack. In addition, the authors analyze the robustness of web services with WS-Security, and security tokens against an XSS attack.
机译:网站与大多数其他软件组件一样,容易受到攻击。跨站点脚本(XSS)攻击是一种恶意代码注入,其中,恶意脚本被注入到网站中。当前,许多网站用于执行称为Web服务的软件组件。我认为,Web服务可以被视为集成不同软件技术的最重要组件。 Web服务安全性(WS-Security)标准中定义的Web服务安全性对于分析XSS攻击很重要。在本文中,作者使用安全测试技术分析了Web服务的健壮性。这是非常实用的论文。作者详细描述了如何测试Web服务中的漏洞,以及如何在攻击者利用它们之前在软件开发过程中发现新的漏洞。本文展示了如何使用某些工具来分析Web服务中漏洞的存在并模拟XSS攻击。另外,作者分析了具有WS-Security的Web服务的健壮性以及针对XSS攻击的安全性令牌。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号