首页> 外文期刊>International Journal of Information Security >A method for identifying Web applications
【24h】

A method for identifying Web applications

机译:识别Web应用程序的方法

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Web applications are ubiquitous in today's busi-nesses. The security of these applications is of utmost impor-tance since security breaches might negatively impact goodreputation, and even result in bankruptcy. There are differentmethods of assessing security of Web applications, mainlybased on some automated method of scanning. One type ofscan method feeds random data to the application and moni-tors its behavior. The other type uses a database with prede-fined vulnerabilities that are checked one by one until eithera vulnerability is found, or it can be claimed that the applica-tion does not have any known vulnerabilities. The importantstep in latter type of scan process is the identification of theapplication since in this case we are narrowing number ofchecks and, as a consequence, the scan process is faster. Thispaper describes a method for Web application identificationbased on a black box principle. Our method is based on theinvariance of certain characteristics of Web applications. Weexperimentally tested and confirmed the usefulness of thisapproach.
机译:Web应用程序在当今的企业中无处不在。这些应用程序的安全性至关重要,因为安全性漏洞可能会对声誉良好产生负面影响,甚至导致破产。评估Web应用程序安全性的方法有很多,主要是基于某种自动化的扫描方法。一种扫描方法将随机数据馈送到应用程序并监控其行为。另一种类型使用具有预先定义的漏洞的数据库,该数据库将被逐一检查,直到找到一个漏洞,或者可以声称该应用程序没有任何已知的漏洞。后一种类型的扫描过程中的重要步骤是识别应用程序,因为在这种情况下,我们缩小了支票的数量,因此,扫描过程更快。本文介绍了一种基于黑盒原理的Web应用程序识别方法。我们的方法基于Web应用程序某些特征的不变性。我们通过实验测试并确认了该方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号