一种新颖的Web服务安全性测试方法
收稿日期: 2010-03-11
修回日期: 2010-06-09
网络出版日期: 2010-09-02
基金资助
国家863计划资助项目(2009AA01Z146)
A New Web Services Security Testing Method
Received date: 2010-03-11
Revised date: 2010-06-09
Online published: 2010-09-02
施寅生,王峰,齐璇 . 一种新颖的Web服务安全性测试方法[J]. 计算机工程与科学, 2010 , 32(9) : 81 -83 . DOI: 10.3969/j.issn.1007130X.2010.
The traditional Web services security testing methods are inefficient,inflexible and do not meet the complex security testing requirements and have difficulty in achieving negative testing. This paper presents a Web services security testing method based on dynamically parsing WSDLs and decomposing security functions. The method solves the problem that traditional testing methods are tightly coupled to the services under testing by dynamically parsing WSDLs. Complex security functions are divided into seven categories of atom security functions so that it can be adapted to complex security testing. It also uses a fault injection mechanism to generate error messages. The experimental results show that the method is flexible,efficient and advanced.
/
| 〈 |
|
〉 |