完整後設資料紀錄
DC 欄位語言
dc.contributor.authorHuang, YWen_US
dc.contributor.authorTsai, CHen_US
dc.contributor.authorLin, TPen_US
dc.contributor.authorHuang, SKen_US
dc.contributor.authorLee, DTen_US
dc.contributor.authorKuo, SYen_US
dc.date.accessioned2014-12-08T15:18:38Z-
dc.date.available2014-12-08T15:18:38Z-
dc.date.issued2005-08-05en_US
dc.identifier.issn1389-1286en_US
dc.identifier.urihttp://dx.doi.org/10.1016/j.comnet.2005.01.003en_US
dc.identifier.urihttp://hdl.handle.net/11536/13405-
dc.description.abstractThe rapid development phases and extremely short turnaround time of Web applications make it difficult to eliminate their vulnerabilities. Here we study how software testing techniques such as fault injection and runtime monitoring can be applied to Web applications. We implemented our proposed mechanisms in the Web Application Vulnerability and Error Scanner (WAVES)-a black-box testing framework for automated Web application security assessment. Real-world situations are used to test WAVES and to compare it with other tools. Our results show that WAVES is a feasible platform for assessing Web application security. (c) 2005 Elsevier B.V. All rights reserved.en_US
dc.language.isoen_USen_US
dc.subjectWeb application testingen_US
dc.subjectsecurity assessmenten_US
dc.subjectfault injectionen_US
dc.subjectblack-box testingen_US
dc.subjectcomplete crawlingen_US
dc.titleA testing framework for Web application security assessmenten_US
dc.typeArticleen_US
dc.identifier.doi10.1016/j.comnet.2005.01.003en_US
dc.identifier.journalCOMPUTER NETWORKSen_US
dc.citation.volume48en_US
dc.citation.issue5en_US
dc.citation.spage739en_US
dc.citation.epage761en_US
dc.contributor.department資訊工程學系zh_TW
dc.contributor.departmentDepartment of Computer Scienceen_US
dc.identifier.wosnumberWOS:000231609300004-
dc.citation.woscount13-
顯示於類別:期刊論文


文件中的檔案:

  1. 000231609300004.pdf

若為 zip 檔案,請下載檔案解壓縮後,用瀏覽器開啟資料夾中的 index.html 瀏覽全文。