首页> 外国专利> Dynamic analysis security testing of multi-party web applications via attack patterns

Dynamic analysis security testing of multi-party web applications via attack patterns

机译:通过攻击模式对多方Web应用程序进行动态分析安全性测试

摘要

A security testing framework leverages attack patterns to generate test cases for evaluating security of Multi-Party Web Applications (MPWAs). Attack patterns comprise structured artifacts capturing key information to execute general-purpose attacker strategies. The patterns recognize commonalities between attacks, e.g., abuse of security-critical parameter(s), and the attacker's strategy relating to protocol patterns associated with those parameters. A testing environment is configured to collect several varieties of HTTP traffic. User interaction with the MPWA while running security protocols, is recorded. An inference module executes the recorded symbolic sessions, tagging elements in the HTTP traffic with labels. This labeled HTTP traffic is referenced to determine particular attack patterns that are to be applied, and corresponding specific attack test cases that are to be executed against the MPWA. Attacks are reported back to the tester for evaluation. Embodiments may be implemented with penetration testing tools, in order to automate execution of complex attacker strategies.
机译:安全测试框架利用攻击模式来生成测试案例,以评估多方Web应用程序(MPWA)的安全性。攻击模式包括捕获关键信息以执行通用攻击者策略的结构化工件。这些模式识别攻击之间的共性,例如,滥用安全关键参数以及与这些参数相关的协议模式有关的攻击者策略。测试环境配置为收集多种HTTP通信。记录运行安全协议时用户与MPWA的交互。推理模块执行记录的符号会话,并使用标签标记HTTP流量中的元素。引用此标记的HTTP流量以确定要应用的特定攻击模式,以及要针对MPWA执行的相应特定攻击测试用例。攻击会报告给测试人员进行评估。实施例可以用渗透测试工具来实现,以便自动执行复杂的攻击者策略。

著录项

  • 公开/公告号US9715592B2

    专利类型

  • 公开/公告日2017-07-25

    原文格式PDF

  • 申请/专利权人 SAP SE;

    申请/专利号US201514885001

  • 申请日2015-10-16

  • 分类号G06F11/00;G06F12/14;G06F12/16;G08B23/00;G06F21/57;H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 13:44:46

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号