• DocumentCode
    2363683
  • Title

    Non-detrimental Web application security scanning

  • Author

    Huang, Yao-Wen ; Tsai, Chung-Hung ; Lee, D.T. ; Kuo, Sy-Yen

  • Author_Institution
    Dept. of Electr. Eng., Nat. Taiwan Univ., Taipei, Taiwan
  • fYear
    2004
  • fDate
    2-5 Nov. 2004
  • Firstpage
    219
  • Lastpage
    230
  • Abstract
    The World Wide Web has become a sophisticated platform capable of delivering a broad range of applications. However, its rapid growth has resulted in numerous security problems that current technologies cannot address. Researchers from both academic and private sector are devoting a considerable amount of resources to the development of Web application security scanners (i.e., automated software testing platforms for Web application security auditing) with some success. However, little is known about their potential side effects. It is possible for an auditing process to induce permanent changes in an application´s state. Due to this potential, we have so far avoided large-scale empirical evaluations of our Web Application Vulnerability and Error Scanner (WAVES). we introduce a testing methodology that allows for harmless auditing, define three testing modes - heavy, relaxed, and safe modes, and report our results from two experiments. In the first, we compared the coverage and side effects of the three scanning modes using 5 real-world Web applications chosen from the 38 found vulnerable in a previous static verification effort. In the second, we used the relaxed mode to conduct a 48-hour test involving 1120 random Web sites, of which 55 were found to be vulnerable.
  • Keywords
    Internet; auditing; program testing; program verification; security of data; Error Scanner; Web Application Vulnerability; Web application security auditing; Web application security scanning; Web site; World Wide Web; automated software testing platform; Application software; Computer science; Filtering; Information science; Information security; Inspection; Large-scale systems; National security; Software testing; Web sites;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Reliability Engineering, 2004. ISSRE 2004. 15th International Symposium on
  • ISSN
    1071-9458
  • Print_ISBN
    0-7695-2215-7
  • Type

    conf

  • DOI
    10.1109/ISSRE.2004.25
  • Filename
    1383120