Title :
Effort Estimates on Web Application Vulnerability Discovery
Author :
Holm, Hannes ; Ekstedt, Mathias ; Sommestad, Teodor
Abstract :
Web application vulnerabilities are widely considered a serious concern. However, there are as of yet scarce data comparing the effectiveness of different security countermeasures or detailing the magnitude of the security issues associated with web applications. This paper studies the effort that is required by a professional penetration tester to find an input validation vulnerability in an enterprise web application that has been developed in the presence or absence of four security measures: (i) developer web application security training, (ii) type-safe API´s, (iii) black box testing tools, or (iv) static code analyzers. The judgments of 21 experts are collected and combined using Cooke´s classical method. The results show that 53 hours is enough to find a vulnerability with a certainty of 95% even though all measures have been employed during development. If no measure is employed 7 hours is enough to find a vulnerability with 95% certainty.
Keywords :
Calibration; Probability distribution; Security; Storage area networks; Testing; Training; Uncertainty;
Conference_Titel :
System Sciences (HICSS), 2013 46th Hawaii International Conference on
Conference_Location :
Wailea, HI, USA
Print_ISBN :
978-1-4673-5933-7
Electronic_ISBN :
1530-1605
DOI :
10.1109/HICSS.2013.190