• DocumentCode
    549440
  • Title

    Web application security: Improving critical web-based applications quality through in-depth security analysis

  • Author

    Teodoro, Nuno ; Serrão, Carlos

  • Author_Institution
    ISCTE-IUL Sch. of Technol. & Archit., ISCTE-IUL Lisbon Univ. Inst., Lisbon, Portugal
  • fYear
    2011
  • fDate
    27-29 June 2011
  • Firstpage
    457
  • Lastpage
    462
  • Abstract
    The Internet, and in particular the World Wide Web, have become one of the most common communication mediums in the World. Millions of users connect everyday to different web-based applications to search for information, exchange messages, interact with each other, conduct business, pay taxes, perform financial operations and many more. Some of these critical web-based services are targeted by several malicious users intending to exploit possible weaknesses and vulnerabilities, which could cause not only the disruption of the service, but also compromise the users and organizations information. Most of the times, these malicious users succeed in exploiting different types of vulnerabilities and the consequences can be disastrous. Most of these vulnerabilities are directly related with the web-based applications lack of quality as a result from a poorly implemented software development life cycle (SDLC). This paper will discuss the direct implication of the lack of security and the importance of quality on the SDLC, and the major factors that influence them. On the other hand the authors propose a set of security automated tools and methodologies that can be used throughout the SDLC as a mean to improve critical web-based applications security and quality.
  • Keywords
    Internet; security of data; software quality; software reliability; Internet; SDLC; Web application security; Web-based applications quality; Web-based services; World Wide Web; communication mediums; in-depth security analysis; malicious users; security automated tools; service disruption; software development life cycle; Encoding; Automated Testing; Critical; Quality; Security; Web Application;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Society (i-Society), 2011 International Conference on
  • Conference_Location
    London
  • Print_ISBN
    978-1-61284-148-9
  • Type

    conf

  • Filename
    5978496