首页> 外文期刊>International Journal of Grid and Utility Computing >A methodology for automated penetration testing of cloud applications
【24h】

A methodology for automated penetration testing of cloud applications

机译:云应用程序自动渗透测试的方法

获取原文
获取原文并翻译 | 示例

摘要

Security assessment is a very time- and money-consuming activity. It needs specialised security skills and, furthermore, it is not fully integrated into the software development life-cycle. One of the best solutions for the security testing of an application relies on the use of penetration testing techniques. Unfortunately, penetration testing is a typically human-driven procedure that requires a deep knowledge of the possible attacks to carry out and of the hacking tools that can be used to launch the tests. In this paper, we present a methodology that enables the automation of penetration testing techniques based on both application-level models, used to represent the application architecture and its security properties in terms of applicable threats, vulnerabilities and weaknesses, and on system-level models, adopted to automatically generate and execute the penetration testing activities. The proposed methodology can be easily integrated into a continuous integration development process and aid software developers in evaluating security.
机译:安全评估是一项非常耗时和金钱的活动。它需要专门的安全技能,而且还没有完全集成到软件开发生命周期中。对应用程序进行安全性测试的最佳解决方案之一就是使用渗透测试技术。不幸的是,渗透测试是通常由人为驱动的过程,需要对可能进行的攻击以及可用于启动测试的黑客工具有深入的了解。在本文中,我们提出了一种方法,该方法可基于两个应用程序级别模型实现渗透测试技术的自动化,用于根据适用的威胁,漏洞和弱点以及系统级模型来表示应用程序体系结构及其安全属性。 ,用于自动生成和执行渗透测试活动。所提出的方法可以轻松地集成到持续集成开发过程中,并帮助软件开发人员评估安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号