• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊
论文

A New Web Services Security Testing Method

Expand
  • (Beijing Institute of System Engineering,Beijing 100101,China)

Received date: 2010-03-11

  Revised date: 2010-06-09

  Online published: 2010-09-02

Abstract

The traditional Web services security testing methods are inefficient,inflexible and do not meet the complex security testing requirements and have difficulty in achieving negative testing. This paper presents a Web services security testing method based on dynamically parsing WSDLs and decomposing security functions. The method solves the problem that traditional testing methods are tightly coupled to the services under testing by dynamically parsing WSDLs. Complex security functions are divided into seven categories of atom security functions so that it can be adapted to complex security testing. It also uses a  fault injection mechanism to generate error messages. The experimental results show that the method is flexible,efficient and advanced.

Cite this article

SHI Yinsheng,WANG Feng,QI Xuan . A New Web Services Security Testing Method[J]. Computer Engineering & Science, 2010 , 32(9) : 81 -83 . DOI: 10.3969/j.issn.1007130X.2010.

Outlines

/