首页> 外国专利> Security testing of web applications with specialised payloads

Security testing of web applications with specialised payloads

机译:具有专用负载的Web应用程序的安全性测试

摘要

Method and system for security testing of web applications comprises; submitting 304 a test to a web application, wherein the test has a payload with a (possibly empty) set of constraints or variables. It further comprises receiving 305 a response from the web application, deriving 308 at least one constraint from the response, and using these to update the previous set of constraints and synthesize 310 a new payload. The test is then repeated 304 by submitting the new payload, and iterating this method until a security vulnerability is discovered 307 or a new payload cannot be constructed under all determined constraints and which possibly respects the grammar of a computer language used. This method may be used to check for input or script that is not sanitised by the web application and thus may be used as a cross-site scripting (XSS) attack. The constraints may be regarded as tokens, and tokens may be replaced with new tokens when generating the new payload.
机译:用于web应用的安全性测试的方法和系统,包括:向网络应用提交304测试,其中该测试具有有效载荷,该有效载荷具有(可能为空)约束或变量集合。它还进一步包括:从网络应用接收305响应,从响应中推导308至少一个约束,并使用这些约束来更新先前的约束集合并合成310新的有效载荷。然后通过提交新的有效载荷来重复304该测试,并且重复该方法直到发现安全漏洞307或不能在所有确定的约束下构造新的有效载荷并且可能尊重所使用的计算机语言的语法。此方法可以用于检查Web应用程序未清除的输入或脚本,因此可以用作跨站点脚本(XSS)攻击。约束可以被视为令牌,并且在生成新的有效载荷时可以用新的令牌替换令牌。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号