Detection and Mitigation of Web Application Vulnerabilities Based on Security Testing - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2012

Detection and Mitigation of Web Application Vulnerabilities Based on Security Testing

Taeseung Lee
  • Fonction : Auteur
  • PersonId : 1011292
Giyoun Won
  • Fonction : Auteur
  • PersonId : 1011293
Seongje Cho
  • Fonction : Auteur
  • PersonId : 1011294
Namje Park
  • Fonction : Auteur
  • PersonId : 1011229
Dongho Won
  • Fonction : Auteur
  • PersonId : 1011295

Résumé

The paper proposes a security testing technique to detect known vulnerabilities of web applications using both static and dynamic analysis. We also present a process to improve the security of web applications by mitigating many of the vulnerabilities revealed in the testing phase, and address a new method for detecting unknown vulnerabilities by applying dynamic black-box testing based on a fuzzing technique. The fuzzing technique includes a structured fuzzing strategy that considers the input data format as well as misuse case generation to enhance the detection rate compared to general fuzzing techniques.
Fichier principal
Vignette du fichier
978-3-642-35606-3_16_Chapter.pdf (275.16 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01551360 , version 1 (30-06-2017)

Licence

Paternité

Identifiants

Citer

Taeseung Lee, Giyoun Won, Seongje Cho, Namje Park, Dongho Won. Detection and Mitigation of Web Application Vulnerabilities Based on Security Testing. 9th International Conference on Network and Parallel Computing (NPC), Sep 2012, Gwangju, South Korea. pp.138-144, ⟨10.1007/978-3-642-35606-3_16⟩. ⟨hal-01551360⟩
100 Consultations
479 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More