J4 ›› 2016, Vol. 38 ›› Issue (01): 73-77.
• 论文 • Previous Articles Next Articles
ZHANG Yufeng,LOU Fang,ZHANG Li
Received:
Revised:
Online:
Published:
Abstract:
Web applications have become the principal model of the internet and enterprise information management. With their popularity, attackers launch malicious attacks via their vulnerability. Security assessment of web applications is a major information security concern. In this paper, we first discuss the formal description of software attack surface via business logic of web applications, and then construct an attack graph model. On such basis, we realize the security assessment in web applications. Based on current general vulnerability detection model, the proposed security assessment model introduces correlation analysis of business logic security. Our proposal overcomes the defects of current testing models of business logic assessment, and achieves fast and comprehensive security assessment of web applications.
Key words: web applications;software attack surface;attack graph;security assessment
ZHANG Yufeng,LOU Fang,ZHANG Li. Security assessment of web applications based on software attack surface [J]. J4, 2016, 38(01): 73-77.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://joces.nudt.edu.cn/EN/
http://joces.nudt.edu.cn/EN/Y2016/V38/I01/73