首页> 外文期刊>Journal of supercomputing >Enlargement of vulnerable web applications for testing
【24h】

Enlargement of vulnerable web applications for testing

机译:扩大易受攻击的Web应用程序以进行测试

获取原文
获取原文并翻译 | 示例

摘要

There are two main kinds of vulnerable web applications, usual applications developed with a specific aim and applications which are vulnerable by design. On one hand, the usual applications are those that are used everywhere and on a daily basis, and where vulnerabilities are detected, and often mended, such as online banking systems, newspaper sites, or any other Web site. On the other hand, vulnerable by design web applications are developed for proper evaluation of web vulnerability scanners and for training in detecting web vulnerabilities. The main drawback of vulnerable by design web applications is that they used to include just a short set of well-known types of vulnerabilities, usually from famous classifications like the OWASP Top Ten. They do not include most of the types of web vulnerabilities. In this paper, an analysis and assessment of vulnerable web applications is conducted in order to select the applications that include the larger set of types of vulnerabilities. Then those applications are enlarged with more types of web vulnerabilities that vulnerable web applications do not include.Lastly, the new vulnerable web applications have been analyzed to check whether web vulnerability scanners are able to detect the new added vulnerabilities, those vulnerabilities that vulnerable by design web applications do not include. The results show that the tools are not very successful in detecting those vulnerabilities, less than well-known vulnerabilities.
机译:易受攻击的Web应用程序主要有两种,一种是针对特定目标开发的常规应用程序,另一种是设计易受攻击的应用程序。一方面,通常的应用是每天到处都在使用的应用程序,这些应用程序检测到漏洞并经常加以修复,例如在线银行系统,报纸网站或任何其他网站。另一方面,开发出易受攻击的Web应用程序是为了对Web漏洞扫描程序进行正确评估并进行有关检测Web漏洞的培训。设计Web应用程序容易受到攻击的主要缺点是,它们过去仅包括一小类众所周知的漏洞类型,通常来自OWASP十大著名分类。它们不包括大多数类型的Web漏洞。在本文中,对易受攻击的Web应用程序进行了分析和评估,以便选择包含更大类型漏洞的应用程序。然后,将这些应用程序扩展为具有更多漏洞类型的Web漏洞,而漏洞Web应用程序不包括这些漏洞。最后,对新的漏洞Web应用程序进行了分析,以检查Web漏洞扫描程序是否能够检测到新添加的漏洞,这些漏洞是设计漏洞而来的。 Web应用程序不包括在内。结果表明,这些工具在检测这些漏洞方面不是很成功,要比众所周知的漏洞少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号