首页> 外文期刊>International Journal of Engineering Research and Applications >Detecting Security Vulnerabilities and Gaps in Web Applications with DevSecOps
【24h】

Detecting Security Vulnerabilities and Gaps in Web Applications with DevSecOps

机译:使用devsecops检测Web应用程序中的安全漏洞和空白

获取原文
       

摘要

With the internet being a common workplace, web applications which are stored in the remote server, delivered, and serviced through the browser interface is used almost as a tool in every business. The surge in the use of web applications is also leading to web application vulnerabilities. A security vulnerability in a web application refers to a misconfiguration in the application code, web servers, application design flaws which an attacker can use to gain full or partial access to the system and exploit the system. Web application vulnerabilities are encountered due improper security headers, broken authentication, account lockout, Injection and Cross Site Request Forgery attacks. Many tools are used to find such vulnerabilities from port level to application level. The concept is to find vulnerabilities from the initial stages of the product cycle itself rather than finding at the end. For the same purpose tools such as Nessus scanner for port level scanning, Zed Attack Proxy for application level of scanning are used. Application specific test cases are written to find vulnerabilities which cannot be found using the tools. This process can be termed as Development-security- operations in the big picture.
机译:通过互联网是一个常见的工作场所,通过浏览器接口提供并服务于远程服务器中的Web应用程序几乎是每个业务中的工具。使用Web应用程序的激增也导致Web应用程序漏洞。 Web应用程序中的安全漏洞是指应用程序代码,Web服务器,应用程序设计缺陷中的错误配置,攻击者可以用于获得对系统的完全或部分访问并利用系统。遇到Web应用程序漏洞由于安全标题,损坏的身份验证,帐户锁定,注入和跨站点请求伪造攻击。许多工具用于查找从端口级别到应用程序级别的漏洞。该概念是从产品周期本身的初始阶段找到漏洞而不是在最后找到。对于相同的目的工具,如用于端口扫描的Nessus扫描仪,使用ZED攻击代理用于应用扫描级别。编写了应用程序特定的测试用例,以查找使用该工具无法找到的漏洞。此过程可以称为大图片中的开发安全操作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号