Experiences in security testing for web-based applications

  • Authors:
  • Chengying Mao

  • Affiliations:
  • Jiangxi University of Finance and Economics, Nanchang, P. R. China

  • Venue:
  • Proceedings of the 2nd International Conference on Interaction Sciences: Information Technology, Culture and Human
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Web-based application is the most prevalent pattern of software system, and has been widely used in the industry and society. However, its security problem brings great harassment to users, such as system crash and economic loss. So it has attracted lots of attention in both academic and industrial community. Although the existing researches have discussed such problem, they mainly focus on a specific security flaw but fail to provide an overall testing guidance. At first, an overall security testing framework for Web-based application is proposed in the paper. Subsequently, the security testing practice for a real-world Web application is carried out, and the corresponding experiences are reported. Test results show that the security testing framework can provide effectual direction for testing practice and reveal valuable security flaws.