...
首页> 外文期刊>Journal of computer sciences >Securing Web Applications through a Framework of Source Code Analysis
【24h】

Securing Web Applications through a Framework of Source Code Analysis

机译:通过源代码分析的框架保护Web应用程序

获取原文

摘要

Source code analysis is becoming extremely important for the universal acceptance of web applications because the automated source code analysis tools play a key role in identifying and fixing security-related vulnerabilities. This paper proposes a framework for securing web applications through source code analysis. The framework has three prescriptive phases including executing and monitoring, classifying and controlling and refining and managing. The framework helps to examine the web application source code related to security issues. The executing and monitoring phase employs five different open source tools for statically analyzing the source code. According to the literature, there are nine broad categories of vulnerabilities in web applications. After filtration of these vulnerabilities, classifying and controlling phase categorize the vulnerabilities according to their severity level with the help of fuzzy analytical analysis process and suggestive measures. The refining and managing phase takes these measures and suggests changes to the source code to make it more secure. This framework was validated through a web-based hospital management system. The results of the validation showed that the framework implementation made the source code more robust towards the upcoming vulnerabilities and bugs.
机译:源代码分析对于普遍接受Web应用程序而言变得非常重要,因为自动源代码分析工具在识别和修复安全相关的漏洞中发挥着关键作用。本文通过源代码分析提出了一种用于保护Web应用程序的框架。该框架有三个规范阶段,包括执行和监控,分类和控制和精炼和管理。该框架有助于检查与安全问题相关的Web应用程序源代码。执行和监控阶段使用五种不同的开源工具,用于静态分析源代码。根据文献,Web应用程序中有九种广泛类别的漏洞。在过滤这些漏洞后,根据模糊分析分析过程和暗示措施,分类和控制阶段根据其严重程度对漏洞进行分类。炼油和管理阶段采用这些措施,并建议更改源代码,以使其更安全。该框架通过基于网络的医院管理系统进行了验证。验证结果表明,框架实现使源代码更强大地迈向即将到来的漏洞和错误。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号