蔡忠宏:Web 應用程式的錯誤殖入測試介面設計

蔡忠宏:Web 應用程式的錯誤殖入測試介面設計

學生 蔡忠宏
年度 92碩
碩士論文 Web 應用程式的錯誤殖入測試介面設計
會議論文 Web application security assessment by fault injection and behavior monitoring
期刊論文 A testing framework for Web application security assessment
摘要 The rapid development phases and extremely short turnaround time of Web applications make it difficult to eliminate their vulnerabilities. Here we study how software testing techniques such as fault injection and runtime monitoring can be applied to Web applications. We implemented our proposed mechanisms in the Web Application Vulnerability and Error Scanner (WAVES)—a black-box testing framework for automated Web application security assessment. Real-world situations are used to test WAVES and to compare it with other tools. Our results show that WAVES is a feasible platform for assessing Web application security.