A testing framework for Web application security assessment

  • Authors:
  • Yao-Wen Huang;Chung-Hung Tsai;Tsung-Po Lin;Shih-Kun Huang;D. T. Lee;Sy-Yen Kuo

  • Affiliations:
  • Department of Electrical Engineering, National Taiwan University, Taipei 106, Taiwan and Institute of Information Science, Academia Sinica, Taipei 115, Taiwan;Institute of Information Science, Academia Sinica, Taipei 115, Taiwan;Institute of Information Science, Academia Sinica, Taipei 115, Taiwan;Department of Electrical Engineering, National Taiwan University, Taipei 106, Taiwan and Department of Computer Science and Information Engineering, National Chiao-Tung University, Hsinchu 300, Ta ...;Department of Electrical Engineering, National Taiwan University, Taipei 106, Taiwan and Institute of Information Science, Academia Sinica, Taipei 115, Taiwan and Department of Computer Science an ...;Department of Electrical Engineering, National Taiwan University, Taipei 106, Taiwan and Institute of Information Science, Academia Sinica, Taipei 115, Taiwan

  • Venue:
  • Computer Networks: The International Journal of Computer and Telecommunications Networking - Web security
  • Year:
  • 2005

Quantified Score

Hi-index 0.01

Visualization

Abstract

The rapid development phases and extremely short turnaround time of Web applications make it difficult to eliminate their vulnerabilities. Here we study how software testing techniques such as fault injection and runtime monitoring can be applied to Web applications. We implemented our proposed mechanisms in the Web Application Vulnerability and Error Scanner (WAVES)-a black-box testing framework for automated Web application security assessment. Real-world situations are used to test WAVES and to compare it with other tools. Our results show that WAVES is a feasible platform for assessing Web application security.