首页> 外国专利> Improved web application auditing based on sub-application identification

Improved web application auditing based on sub-application identification

机译:基于子应用程序标识的改进的Web应用程序审核

摘要

A web application is more efficiently analyzed by identifying the sub-applications used to generate the various web pages available at the web application and then limiting the vulnerability assessment to just a subset of the web pages generated by each sub-application. The sub-applications can be identified by detecting similarity between the web pages, based on the user interface presentation, the inputs required or allowed, or both. For the user interface presentation, the markup language used to generate the user interface is reduced to common markup language elements by removing content, attribute values and white space and then determining the edit distances between the various pages. Small edit distance values indicate similarity and thus, likely generated by a common sub-application.
机译:通过标识用于生成Web应用程序上可用的各种网页的子应用程序,然后将漏洞评估限制为每个子应用程序生成的网页的子集,可以更有效地分析Web应用程序。可以通过基于用户界面表示,所需或允许的输入或两者来检测网页之间的相似性来标识子应用程序。对于用户界面表示,通过删除内容,属性值和空白,然后确定各个页面之间的编辑距离,可以将用于生成用户界面的标记语言简化为通用标记语言元素。较小的编辑距离值表示相似,因此很可能是由公共子应用程序生成的。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号