Go to:
Logótipo
Comuta visibilidade da coluna esquerda
Você está em: Start > Publications > View > Pattern based Web Security Testing
Publication

Publications

Pattern based Web Security Testing

Title
Pattern based Web Security Testing
Type
Article in International Conference Proceedings Book
Year
2018-01-20
Authors
Ana C. R. Paiva
(Author)
FEUP
View Personal Page You do not have permissions to view the institutional email. Search for Participant Publications View Authenticus page View ORCID page
Paulo J. M. Araújo
(Author)
Other
Indexing
Publicação em Scopus Scopus - 0 Citations
INSPEC
Other information
Authenticus ID: P-00N-V5Q
Abstract (EN): This paper presents a Pattern Based Testing approach for testing security aspects of the applications under test (AUT). It describes the two security patterns which are the focus of this work (¿Account Lockout¿ and ¿Authentication Enforcer¿) and the test strategies implemented to check if the applications are vulnerable or not regarding these patterns. The PBST (Pattern Based Security Testing) overall approach has two phases: exploration (to identify the web pages of the application under test) and testing (to execute the test strategies developed in order to detect vulnerabilities). An experiment is presented to validate the approach over five public web applications. The goal is to assess the behavior of the tool when varying the upper limit of pages to visit and assess its capacity to find real vulnerabilities. The results are promising. Indeed, it was possible to check that the vulnerabilities detected corresponded to real security problems. Copyright
Language: English
Type (Professor's evaluation): Scientific
Documents
We could not find any documents associated to the publication.
Recommend this page Top
Copyright 1996-2025 © Faculdade de Direito da Universidade do Porto  I Terms and Conditions  I Acessibility  I Index A-Z
Page created on: 2025-08-08 at 03:43:32 | Privacy Policy | Personal Data Protection Policy | Whistleblowing