首页> 外文期刊>Software Testing, Verification and Reliability >MobSTer: Amodel-based security testing framework for web applications
【24h】

MobSTer: Amodel-based security testing framework for web applications

机译:MobSTer:用于Web应用程序的基于Amodel的安全测试框架

获取原文
获取原文并翻译 | 示例

摘要

Web applications have become one of the preferred means for users to perform a number of crucial and security-sensitive operations such as selling and buying goods or managing bank accounts, official documents, personal health records, and smart houses. The pervasive adoption of such web applications calls for an extensive security analysis in order to avoid attacks. Penetration testing is the most common approach for testing the security of web applications, but model-based security testing has been steadily maturing into a viable alternative and/or complementary approach. Penetration testing is very efficient, but the experience of the security analyst is crucial; model-based security testing relies on formal methods, but the security analyst has to first create a suitable model of the web application. In this paper, we introduce MobSTer, a formal and flexible model-based security testing framework that contributes to filling the gap between these two security testing approaches. The main idea underlying this framework is that the use of model-checking techniques can automate the search for possible vulnerable entry points in the web application, ie, it permits an analyst to perform security testing without missing important checks. Moreover, the framework also allows for reuse: The analyst can collect her expertise into the framework and (re)use it during future tests on possibly different web applications. We have implemented MobSTer as a prototype and applied it to test a number of case studies to assess its strength and concretely evaluate it with respect to four state-of-the-art tools normally used by penetration testers.
机译:Web应用程序已成为用户执行许多关键且对安全性敏感的操作(例如买卖商品或管理银行帐户,正式文件,个人健康记录和智能房屋)的首选手段之一。此类Web应用程序的广泛采用要求进行广泛的安全性分析,以避免攻击。渗透测试是测试Web应用程序安全性的最常用方法,但是基于模型的安全性测试已稳步成熟为可行的替代和/或补充方法。渗透测试非常有效,但是安全分析师的经验至关重要。基于模型的安全测试依赖于形式化方法,但是安全分析人员必须首先创建合适的Web应用程序模型。在本文中,我们介绍MobSTer,这是一种基于模型的正式,灵活的安全测试框架,它有助于填补这两种安全测试方法之间的空白。该框架的主要思想是使用模型检查技术可以自动搜索Web应用程序中可能存在的漏洞入口点,即,它允许分析师执行安全测试而不会丢失重要检查。此外,该框架还允许重用:分析人员可以将其专业知识收集到框架中,并在将来对可能不同的Web应用程序进行测试时(重新)使用它。我们已将MobSTer用作原型,并将其用于测试许多案例研究以评估其强度,并针对渗透测试人员通常使用的四种最新工具进行具体评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号