메뉴 건너뛰기




Volumn , Issue , 2010, Pages 332-345

State of the art: Automated black-box web application vulnerability testing

Author keywords

Black box testing; Security standards compliance; Vulnerability detection; Web application security

Indexed keywords

AUTOMATED TOOLS; BLACK BOXES; BLACK-BOX TESTING; COMPARATIVE DATA; CROSS-SITE SCRIPTING; SECURITY STANDARDS; SECURITY VULNERABILITIES; SPECIFIC TOOL; SQL INJECTION; STATE OF THE ART; VULNERABILITY DETECTION; WEB APPLICATION; WEB APPLICATION SECURITY; WEB APPLICATION VULNERABILITY;

EID: 77955207391     PISSN: 10816011     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1109/SP.2010.27     Document Type: Conference Paper
Times cited : (247)

References (35)
  • 1
    • 77955219882 scopus 로고    scopus 로고
    • [Online]. Available: http://blogs.zdnet.com/security/?p=3514
    • StrongWebmail CEO's mail account hacked via XSS. ZDNet. [Online]. Available: http://blogs.zdnet.com/security/?p=3514
    • StrongWebmail CEO's Mail Account Hacked Via XSS
  • 4
    • 77955206201 scopus 로고    scopus 로고
    • Payment Card Industry Security Standards Council. [Online]. Available
    • Approved Scanning Vendors. Payment Card Industry Security Standards Council. [Online]. Available: https://www.pcisecuritystandards.org/pdfs/asv report.html
    • Approved Scanning Vendors
  • 5
    • 77955223656 scopus 로고    scopus 로고
    • [Online]. Available
    • VUPEN Security. [Online]. Available: http://www.vupen.com
  • 6
    • 77955211998 scopus 로고    scopus 로고
    • Dept. of Homeland Security National Cyber Security Division. [Online]. Available
    • National Vulnerability Database. Dept. of Homeland Security National Cyber Security Division. [Online]. Available:http://web.nvd.nist.gov
  • 8
    • 84873832099 scopus 로고    scopus 로고
    • [Online]. Available
    • Web Application Security Scanner Evaluation Criteria. Web Application Security Consortium. [Online]. Available: http://projects.webappsec.org/Web- Application-Security-Scanner-Evaluation-Criteria
    • Web Application Security Consortium
  • 9
    • 77955205925 scopus 로고    scopus 로고
    • [Online]. Available
    • OWASP Top Ten Project. Open Web Application Security Project. [Online]. Available: http://www.owasp.org/index.php/Category:OWASP-Top-Ten-Project
    • Open Web Application Security Project
  • 10
    • 84873832099 scopus 로고    scopus 로고
    • [Online]. Available
    • Web Security Threat Classification. Web Application Security Consortium. [Online]. Available: http://www.webappsec.org/projects/threat/
    • Web Application Security Consortium
  • 11
    • 77955199688 scopus 로고    scopus 로고
    • [Online]. Available
    • Common Weakness Enumeration. [Online]. Available: http://cwe.mitre.org
  • 13
    • 77955178987 scopus 로고    scopus 로고
    • [Online]. Available
    • Common Vulnerabilities and Exposures. [Online]. Available: http://cve.mitre.org
  • 14
    • 77955208377 scopus 로고    scopus 로고
    • Black ops of PKI
    • August
    • D. Kaminsky, "Black Ops of PKI," BlackHat USA, August 2009.
    • (2009) BlackHat USA
    • Kaminsky, D.1
  • 15
    • 78649901040 scopus 로고    scopus 로고
    • More tricks for defeating SSL
    • August
    • M. Marlinspike, "More Tricks For Defeating SSL," BlackHat USA, August 2009.
    • (2009) BlackHat USA
    • Marlinspike, M.1
  • 16
    • 85027442855 scopus 로고    scopus 로고
    • Our favorite XSS filters and how to attack them
    • August
    • E. V. Nava and D. Lindsay, "Our Favorite XSS Filters and How to Attack Them," BlackHat USA, August 2009.
    • (2009) BlackHat USA
    • Nava, E.V.1    Lindsay, D.2
  • 17
    • 77955199184 scopus 로고    scopus 로고
    • [Online]. Available
    • Open Web Application Security Project. [Online]. Available: http://www.owasp.org
  • 18
    • 77955216234 scopus 로고    scopus 로고
    • [Online]. Available
    • Web Application Security Consortium. [Online]. Available: http://www.wasc.org
  • 19
    • 84873832099 scopus 로고    scopus 로고
    • [Online]. Available
    • Web Application Security Statistics. Web Application Security Consortium. [Online]. Available: http://projects.webappsec.org/Web-Application-Security- Statistics
    • Web Application Security Consortium
  • 20
    • 35449004893 scopus 로고    scopus 로고
    • Sound and precise analysis of web applications for injection vulnerabilities
    • G. Wassermann and Z. Su, "Sound and precise analysis of web applications for injection vulnerabilities," SIGPLAN Not., vol. 42, no. 6, pp. 32-41, 2007.
    • (2007) SIGPLAN Not , vol.42 , Issue.6 , pp. 32-41
    • Wassermann, G.1    Su, Z.2
  • 23
    • 33751027156 scopus 로고    scopus 로고
    • Pixy: A static analysis tool for detecting web application vulnerabilities (short paper)
    • [Online]. Available
    • N. Jovanovic, C. Kruegel, and E. Kirda, "Pixy: A static analysis tool for detecting web application vulnerabilities (short paper)," in 2006 IEEE Symposium on Security and Privacy, 2006, pp. 258-263. [Online]. Available: http://www.iseclab.org/papers/pixy.pdf
    • (2006) 2006 IEEE Symposium on Security and Privacy , pp. 258-263
    • Jovanovic, N.1    Kruegel, C.2    Kirda, E.3
  • 27
    • 76649142367 scopus 로고    scopus 로고
    • Protecting a moving target: Addressing web application concept drift
    • F. Maggi, W. K. Robertson, C. Kr̈ugel, and G. Vigna, "Protecting a moving target: Addressing web application concept drift," in RAID, 2009, pp. 21-40.
    • (2009) RAID , pp. 21-40
    • Maggi, F.1    Robertson, W.K.2    Kr̈ugel, C.3    Vigna, G.4
  • 29
    • 77955214170 scopus 로고    scopus 로고
    • [Online]. Available
    • Powerfuzzer. [Online]. Available: http://www.powerfuzzer.com/
  • 30
    • 77955208628 scopus 로고    scopus 로고
    • [Online]. Available
    • CIRT.net Nikto Scanner. [Online]. Available: http://cirt.net/nikto2
  • 31
    • 77955213907 scopus 로고    scopus 로고
    • [Online]. Available
    • WebGoat Project. OWASP. [Online]. Available: http://www.owasp.org/index. php/Category:OWASP-WebGoat-Project
  • 32
    • 77955190033 scopus 로고    scopus 로고
    • McAfee Corp. [Online]. Available
    • HacmeBank. McAfee Corp. [Online]. Available: http://www.foundstone.com/ us/resources/proddesc/hacmebank.htm
  • 33
    • 77955179762 scopus 로고    scopus 로고
    • AltoroMutual Bank. Watchfire Corp. [Online]. Available
    • AltoroMutual Bank. Watchfire Corp. [Online]. Available:http://demo. testfire.net/
  • 34
    • 77955218299 scopus 로고    scopus 로고
    • [Online]. Available
    • Larry Suto. Analyzing the Accuracy and Time Costs of Web Application Security Scanners. [Online]. Available: http://ha.ckers.org/files/Accuracy-and- Time-Costs-of-Web-App-Scanners.pdf
    • Suto, L.1
  • 35
    • 50049110333 scopus 로고    scopus 로고
    • Testing and comparing web vulnerability scanning tools for sql injection and xss attacks
    • vol. 0
    • J. Fonseca, M. Vieira, and H. Madeira, "Testing and comparing web vulnerability scanning tools for sql injection and xss attacks," Pacific Rim Int'l Symp. Dependable Computing, IEEE, vol. 0, pp. 365-372, 2007.
    • (2007) Pacific Rim Int'l Symp. Dependable Computing, IEEE , pp. 365-372
    • Fonseca, J.1    Vieira, M.2    Madeira, H.3


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.