메뉴 건너뛰기




Volumn 83, Issue 11, 2010, Pages 2263-2274

Perturbation-based user-input-validation testing of web applications

Author keywords

Software testing; User input validation testing; Web application testing

Indexed keywords

APPLICATION-LEVEL ATTACKS; EMPIRICAL RESULTS; EMPIRICAL STUDIES; NEW APPROACHES; SIDE INFORMATION; TEST INPUTS; TEST TOOLS; VALIDATION TESTING; VULNERABILITY SCANNER; WEB APPLICATION; WEB-APPLICATION TESTING;

EID: 77957332722     PISSN: 01641212     EISSN: None     Source Type: Journal    
DOI: 10.1016/j.jss.2010.07.007     Document Type: Article
Times cited : (31)

References (48)
  • 1
    • 77957364528 scopus 로고    scopus 로고
    • Acunetix Web Vulnerability Scanner
    • Acunetix Web Vulnerability Scanner, http://www.acunetix.com/ (2008).
    • (2008)
  • 2
    • 22144441364 scopus 로고    scopus 로고
    • Testing web applications by modeling with fsms
    • A. Andrews, J. Offutt, and R. Alexander Testing web applications by modeling with fsms Software Syst. Model. 4 3 2005 326 345
    • (2005) Software Syst. Model. , vol.4 , Issue.3 , pp. 326-345
    • Andrews, A.1    Offutt, J.2    Alexander, R.3
  • 3
    • 77957350077 scopus 로고    scopus 로고
    • Appscan Suite for Web Application Security Testing
    • Appscan Suite for Web Application Security Testing, http://www.watchfire. com/products/appscan/default.aspx (2008).
    • (2008)
  • 7
    • 77957375476 scopus 로고    scopus 로고
    • Burp proxy, http://www.portswigger.net/proxy/ (2009).
  • 9
    • 77957349552 scopus 로고    scopus 로고
    • dk.brics.automaton, http://www.brics.dk/automaton/index.html (2007).
    • (2007)
  • 10
    • 0037925531 scopus 로고    scopus 로고
    • Improving web application testing with user session data
    • S. Elbaum, S. Karre, and G. Rothermel Improving web application testing with user session data Proc. ICSE 2003 49 59
    • (2003) Proc. ICSE , pp. 49-59
    • Elbaum, S.1    Karre, S.2    Rothermel, G.3
  • 11
  • 12
    • 77957376033 scopus 로고    scopus 로고
    • Fiddler, http://www.fiddlertool.com/fiddler/ (2009).
  • 14
    • 77957357859 scopus 로고    scopus 로고
    • Google Hacking Database, http://johnny.ihackstuff.com/ghdb.php (2008).
  • 15
    • 77957333314 scopus 로고    scopus 로고
    • HTML DOM Tutorial, http://www.w3schools.com/HTMLDOM/default.asp (2009).
    • (2009)
  • 16
    • 37849004456 scopus 로고    scopus 로고
    • Improving test case generation for web applications using automated interface discovery
    • W.G.J. Halfond, and A. Orso Improving test case generation for web applications using automated interface discovery Proc. ESEC-FSE 2007 145 154
    • (2007) Proc. ESEC-FSE , pp. 145-154
    • Halfond, W.G.J.1    Orso, A.2
  • 17
    • 0016518550 scopus 로고
    • A linear space algorithm for computing maximal common subsequences
    • D. Hirschberg A linear space algorithm for computing maximal common subsequences Commun. ACM 18 6 1975 341 343
    • (1975) Commun. ACM , vol.18 , Issue.6 , pp. 341-343
    • Hirschberg, D.1
  • 19
    • 77957371116 scopus 로고    scopus 로고
    • HTML Parser, http://htmlparser.sourceforge.net/ (2006).
    • (2006)
  • 20
    • 84880450431 scopus 로고    scopus 로고
    • Web application security assessment by fault injection and behavior monitoring
    • Y. Huang, S. Huang, T. Lin, and C. Tsai Web application security assessment by fault injection and behavior monitoring Proc. WWW 2003 148 159
    • (2003) Proc. WWW , pp. 148-159
    • Huang, Y.1    Huang, S.2    Lin, T.3    Tsai, C.4
  • 21
    • 19944365247 scopus 로고    scopus 로고
    • Securing web application code by static analysis and runtime protection
    • Y.W. Huang, F. Yu, C. Hang, C. Tsai, D.T. Lee, and S. Kuo Securing web application code by static analysis and runtime protection Proc. WWW 2004 40 52
    • (2004) Proc. WWW , pp. 40-52
    • Huang, Y.W.1    Yu, F.2    Hang, C.3    Tsai, C.4    Lee, D.T.5    Kuo, S.6
  • 23
    • 77957345202 scopus 로고    scopus 로고
    • Koders, http://www.koders.com/ (2008).
    • (2008)
  • 25
    • 47849097820 scopus 로고    scopus 로고
    • Automated verification and test case generation for input validation
    • H. Liu, and H.B.K. Tan Automated verification and test case generation for input validation Proc. AST 2006 9 14
    • (2006) Proc. AST , pp. 9-14
    • Liu, H.1    Tan, H.B.K.2
  • 26
    • 84960478058 scopus 로고    scopus 로고
    • Object-based data flow testing of web applications
    • C.-H. Liu, D.C. Kung, P. Hsia, and C.-T. Hsu Object-based data flow testing of web applications Proc. APAQS 2000 7 16
    • (2000) Proc. APAQS , pp. 7-16
    • Liu, C.-H.1    Kung, D.C.2    Hsia, P.3    Hsu, C.-T.4
  • 28
    • 33750613475 scopus 로고    scopus 로고
    • Testing web-based applications: The state of the art and future trends
    • G.A.D. Lucca, and A.R. Fasolino Testing web-based applications: the state of the art and future trends Inf. Softw. Technol. 48 12 2006 1172 1186
    • (2006) Inf. Softw. Technol. , vol.48 , Issue.12 , pp. 1172-1186
    • Lucca, G.A.D.1    Fasolino, A.R.2
  • 30
    • 35348851548 scopus 로고    scopus 로고
    • Using a competitive clustering algorithm to comprehend web applications
    • A.D. Lucia, G. Scanniello, and G. Tortora Using a competitive clustering algorithm to comprehend web applications Proc. WSE 2006 33 40
    • (2006) Proc. WSE , pp. 33-40
    • Lucia, A.D.1    Scanniello, G.2    Tortora, G.3
  • 31
    • 84976657294 scopus 로고
    • The complexity of some problems on subsequences and supersequences
    • D. Maier The complexity of some problems on subsequences and supersequences J. ACM 25 2 1978 322 336
    • (1978) J. ACM , vol.25 , Issue.2 , pp. 322-336
    • Maier, D.1
  • 32
    • 77957347849 scopus 로고    scopus 로고
    • Mvnforum, http://www.mvnforum.com/mvnforumweb/index.jsp (2006).
    • (2006)
  • 33
    • 77957329728 scopus 로고    scopus 로고
    • Nikto2 release 2.02, http://www.cirt.net/code/nikto.shtml (2008).
    • (2008)
  • 34
    • 77957330270 scopus 로고    scopus 로고
    • NIST SAMATE Reference Dataset Project, http://samate.nist.gov/SRD/index. php (2007).
    • (2007)
  • 35
  • 36
    • 77957327515 scopus 로고    scopus 로고
    • Open Source Vulnerability Database, http://osvdb.org/ (2008).
    • (2008)
  • 37
    • 77957364014 scopus 로고    scopus 로고
    • Open Web Application Security Project, Top 10 2007. http://www.owasp.org/ index.php/Top-10-2007.
  • 38
    • 77957329450 scopus 로고    scopus 로고
    • for Web Application Security Assessment
    • Paros - for Web Application Security Assessment, http://www.parosproxy. org/index.shtml (2008).
    • (2008)
  • 40
    • 77957360857 scopus 로고    scopus 로고
    • Regular Expression Library, http://regexlib.com/ (2007).
  • 41
    • 0035009417 scopus 로고    scopus 로고
    • Analysis and testing of web applications
    • F. Ricca, and P. Tonella Analysis and testing of web applications Proc. ICSE 2001 25 34
    • (2001) Proc. ICSE , pp. 25-34
    • Ricca, F.1    Tonella, P.2
  • 42
    • 77951454839 scopus 로고    scopus 로고
    • Automated replay and failure detection for web applications
    • S. Sprenkle, E. Gibson, S. Sampath, and L. Pollock Automated replay and failure detection for web applications Proc. ASE 2005 253 262
    • (2005) Proc. ASE , pp. 253-262
    • Sprenkle, S.1    Gibson, E.2    Sampath, S.3    Pollock, L.4
  • 43
    • 77957331120 scopus 로고    scopus 로고
    • Tamperie, http://www.bayden.com/TamperIE/ (2009).
    • (2009)
  • 45
    • 77957340126 scopus 로고    scopus 로고
    • Top 10 Web Vulnerability Scanners
    • Top 10 Web Vulnerability Scanners, http://sectools.org/web-scanners.html (2006).
    • (2006)
  • 46
    • 18844408627 scopus 로고    scopus 로고
    • Online testing of web-based applications
    • Q. Wang, L. Quan, and F. Ying Online testing of web-based applications Proc. COMPSAC 2004 166 169
    • (2004) Proc. COMPSAC , pp. 166-169
    • Wang, Q.1    Quan, L.2    Ying, F.3
  • 48
    • 77957342674 scopus 로고    scopus 로고
    • Wikto: Web Server Assessment Tool, http://www.sensepost.com/research/ wikto/ (2008).
    • (2008)


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.