首页> 外文期刊>International journal of dependable and trustworthy information systems >Selecting Secure Web Applications Using Trustworthiness Benchmarking
【24h】

Selecting Secure Web Applications Using Trustworthiness Benchmarking

机译:使用可信赖性基准测试选择安全的Web应用程序

获取原文
获取原文并翻译 | 示例
       

摘要

The multiplicity of existing software and component alternatives for web applications, especially in open source communities, has boosted interest in suitable benchmarks, able to assist in the selection of candidate solutions, concerning several quality attributes. However, the huge success of performance and dependability benchmarking contrasts the small advances in security benchmarking. Traditionalvulnerability/attackdetection techniques can hardly be used alone to benchmark security, as security depends on hidden vulnerabilities and subtle properties of the system and its environment. A comprehensive security benchmarking process should consist of a two-step process: elimination of flawedalternativesfollowed bytrustworthiness benchmarking. In this paper, the authors propose a trustworthiness benchmark based on the systematic collection of evidences that can be used to select one among several web applications, from a security point-of-view. They evaluate this benchmark approach by comparing its results with an evaluation conducted by a group of security experts and programmers. Results show that the proposed benchmark provides security rankings similar to those provided by human experts. In fact, although experts may take days to gather the information and rank the alternative web applications, the benchmark consistently provides similar results in a matter of few minutes.
机译:Web应用程序的现有软件和组件替代方案的多样性,尤其是在开放源代码社区中,已经引起了人们对合适基准的兴趣,这些基准可以帮助选择涉及多个质量属性的候选解决方案。但是,性能和可靠性基准测试的巨大成功与安全基准测试的小进步形成了鲜明的对比。传统的漏洞/攻击检测技术几乎不能单独用于对安全性进行基准测试,因为安全性取决于系统及其环境的隐藏漏洞和微妙特性。全面的安全基准测试过程应包括两个步骤:消除可信任基准测试之后的有缺陷的替代方法。在本文中,作者基于系统的证据收集提出了一个可信赖性基准,可以从安全的角度来从几个Web应用程序中选择一个。他们通过将其结果与一组安全专家和程序员进行的评估相比较来评估这种基准方法。结果表明,建议的基准所提供的安全性等级与人类专家提供的安全性等级相似。实际上,尽管专家可能需要花费数天的时间来收集信息并对备用Web应用程序进行排名,但该基准测试在几分钟之内始终能够提供相似的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号