...
首页> 外文期刊>International Journal of Information Security >Designing vulnerability testing tools for web services: approach, components, and tools
【24h】

Designing vulnerability testing tools for web services: approach, components, and tools

机译:设计Web服务的漏洞测试工具:方法,组件和工具

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

This paper proposes a generic approach for designing vulnerability testing tools for web services, which includes the definition of the testing procedure and the tool components. Based on the proposed approach, we present the design of three innovative testing tools that implement three complementary techniques (improved penetration testing, attack signatures and interface monitoring, and runtime anomaly detection) for detecting injection vulnerabilities, thus offering an extensive support for different scenarios. A case study has been designed to demonstrate the tools for the particular case of SQL Injection vulnerabilities. The experimental evaluation demonstrates that the tools can effectively be used in different scenarios and that they outperform well-known commercial tools by achieving higher detection coverage and lower false-positive rates.
机译:本文提出了一种为Web服务设计漏洞测试工具的通用方法,包括测试过程和工具组件的定义。 基于所提出的方法,我们介绍了三种创新测试工具的设计,实现了三种互补技术(改进了穿透性测试,攻击签名和接口监测和运行时异常检测),用于检测注射漏洞,从而为不同的场景提供了广泛的支持。 案例研究旨在展示SQL注入漏洞的特定情况的工具。 实验评估表明,通过实现更高的检测覆盖和较低的假阳性率,可以有效地使用不同的场景,并且它们优于众所周知的商业工具。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号