Towards benchmarking the trustworthiness of web applications code

  • Authors:
  • Afonso Araújo Neto;Marco Vieira

  • Affiliations:
  • University of Coimbra, Coimbra, Portugal;University of Coimbra, Coimbra, Portugal

  • Venue:
  • EWDC '11 Proceedings of the 13th European Workshop on Dependable Computing
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Comparing the security of web applications is very hard and, although there are many proposals of security metrics in the literature, no consensual quantitative security metric has been proposed so far. In this paper we study the use of trust-based metrics as an alternative for benchmarking the security of web applications code. The approach consists of quantifying and exposing evidences that show that developers applied valuable best practices to prevent potential security vulnerabilities, thus improving the trustworthiness that can be justifiably put in the application. The idea is that the metrics should portray the relative level of trust users can put in an application regarding its ability to prevent attacks. To demonstrate the idea we conducted a preliminary experimental evaluation using two implementations of a complex Web Service. Although further research is needed, preliminary results suggest that trust-based metrics are a promising approach to compare web applications in terms of security features.