...
首页> 外文期刊>Empirical Software Engineering >An empirical investigation into open source web applications' implementation vulnerabilities
【24h】

An empirical investigation into open source web applications' implementation vulnerabilities

机译:对开源Web应用程序实现漏洞的实证研究

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Current web applications have many inherent vulnerabilities; in fact, in 2008, over 63% of all documented vulnerabilities are for web applications. While many approaches have been proposed to address various web application vulnerability issues, there has not been a study to investigate whether these vulnerabilities share any common properties. In this paper, we use an approach similar to the Goal-Question-Metric approach to empirically investigate four questions regarding open source web applications vulnerabilities: What proportion of security vulnerabilities in web applications can be considered as implementation vulnerabilities? Are these vulnerabilities the result of interactions between web applications and external systems? What is the proportion of vulnerable lines of code within a web application? Are implementation vulnerabilities caused by implicit or explicit data flows? The results from the investigation show that implementation vulnerabilities dominate. They are caused through interactions between web applications and external systems. Furthermore, these vulnerabilities only contain explicit data flows, and are limited to relatively small sections of the source code.
机译:当前的Web应用程序具有许多固有的漏洞。实际上,在2008年,记录在案的所有漏洞中有63%以上是针对Web应用程序的。尽管已经提出了许多方法来解决各种Web应用程序漏洞问题,但是还没有一项研究来研究这些漏洞是否共享任何公共属性。在本文中,我们使用类似于“目标-问题-度量”方法的方法,以经验方式调查有关开源Web应用程序漏洞的四个问题:Web应用程序中的安全漏洞中有多少比例可以视为实现漏洞?这些漏洞是Web应用程序与外部系统之间交互的结果吗? Web应用程序中易受攻击的代码行的比例是多少?实现漏洞是由隐式或显式数据流引起的吗?调查结果表明,实施漏洞占主导地位。它们是由Web应用程序与外部系统之间的交互引起的。此外,这些漏洞仅包含显式数据流,并且仅限于源代码的较小部分。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号