메뉴 건너뛰기




Volumn , Issue , 2011, Pages 104-111

Enhancing penetration testing with attack signatures and interface monitoring for the detection of injection vulnerabilities in web services

Author keywords

Attack signatures; Interface monitoring; Penetration testing; Security; Vulnerability detection; Web services

Indexed keywords

ATTACK SIGNATURE; CRITICAL SOFTWARE; DETECTION COVERAGE; DEVELOPMENT SCENARIOS; EXPERIMENTAL EVALUATION; FALSE POSITIVE; INTERNAL STATE; PENETRATION TESTING; PROTOTYPE TOOLS; SECURITY; SQL INJECTION; VULNERABILITY DETECTION;

EID: 80053169173     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1109/SCC.2011.67     Document Type: Conference Paper
Times cited : (30)

References (28)
  • 3
    • 0041686586 scopus 로고    scopus 로고
    • Sebasto-pol, CA, USA: O'Reilly & Associates, Inc.
    • D.A. Chappell and T. Jewell, Java Web Services, Sebasto-pol, CA, USA: O'Reilly & Associates, Inc., 2002.
    • (2002) Java Web Services
    • Chappell, D.A.1    Jewell, T.2
  • 8
    • 78650820717 scopus 로고    scopus 로고
    • Detecting security vulnerabilities in web applications using dynamic analysis with penetration testing
    • A. Petukhov and D. Kozlov, "Detecting Security Vulnerabilities in Web Applications Using Dynamic Analysis with Penetration Testing," Proceedings of the Application Security Conference, 2008.
    • (2008) Proceedings of the Application Security Conference
    • Petukhov, A.1    Kozlov, D.2
  • 12
    • 84872431733 scopus 로고    scopus 로고
    • IBM, "IBM Rational AppScan" Available: http://www-01.ibm.com/ software/awdtools/appscan/.
    • IBM Rational AppScan
  • 13
    • 80455151022 scopus 로고    scopus 로고
    • HP, "HP WebInspect" Available: https://h10078.www1.hp.com/cda/ hpms/display/main/hpms-content.jsp?zn=bto&cp=1-11-201-200%5E9570-4000-100-.
    • HP WebInspect
  • 14
    • 80053161103 scopus 로고    scopus 로고
    • Foundstone WSDigger
    • Foundstone, Inc., "Foundstone WSDigger," Foundstone Free Tools Available: http://www.foundstone.com/us/resources/proddesc/wsdigger.htm.
    • Foundstone Free Tools
  • 15
    • 80053159622 scopus 로고    scopus 로고
    • OWASP Foundation, "OWASP WSFuzzer Project" Available: http://www.owasp.org/index.php/Category:OWASP-WSFuzzer-Project.
    • OWASP WSFuzzer Project
  • 18
    • 70350776534 scopus 로고    scopus 로고
    • Detecting SQL injection vulnerabilities in web services
    • Joao Pessoa, Brazil: IEEE Computer Society
    • N. Antunes and M. Vieira, "Detecting SQL Injection Vulnerabilities in Web Services," Fourth Latin-American Symposium on Dependable Computing, Joao Pessoa, Brazil: IEEE Computer Society, 2009, pp. 17-24.
    • (2009) Fourth Latin-American Symposium on Dependable Computing , pp. 17-24
    • Antunes, N.1    Vieira, M.2
  • 21
    • 49649112245 scopus 로고    scopus 로고
    • Why machine learning algorithms fail in misuse detection on KDD intrusion detection data set
    • M. Sabhnani and G. Serpen, "Why machine learning algorithms fail in misuse detection on KDD intrusion detection data set," Intelligent Data Analysis, vol. 8, 2004.
    • (2004) Intelligent Data Analysis , vol.8
    • Sabhnani, M.1    Serpen, G.2
  • 22
    • 58149169229 scopus 로고    scopus 로고
    • Ethereal vs. Tcpdump: A comparative study on packet sniffing tools for educational purpose
    • F. Fuentes and D.C. Kar, "Ethereal vs. Tcpdump: a comparative study on packet sniffing tools for educational purpose," Journal of Computing Sciences in Colleges, vol. 20, 2005, p. 169-176.
    • (2005) Journal of Computing Sciences in Colleges , vol.20 , pp. 169-176
    • Fuentes, F.1    Kar, D.C.2
  • 23
    • 80053163531 scopus 로고    scopus 로고
    • LittleShoot, "LittleProxy HTTP Proxy" Available: http://www.littleshoot.org/littleproxy/.
    • LittleProxy HTTP Proxy
  • 28
    • 80053156440 scopus 로고    scopus 로고
    • Campwood Software, "SourceMonitor Version 2.5" Available: http://www.campwoodsw.com/sourcemonitor.html.
    • SourceMonitor Version 2.5


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.