Pregled bibliografske jedinice broj: 359316
Detecting Vulnerabilities in Web Applications by Clustering Web Pages
Detecting Vulnerabilities in Web Applications by Clustering Web Pages // Proc. 31st Int'l Convention MIPRO 2008, Vol. V: Digital Economy - 5th ALADIN, Information Systems Security, Business Intelligence Systems, Local Government, Student Papers / Čišić, Dragan ; Hutinski, Željko ; Baranović, Mirtas ; Mauher, Mladen ; Dragšić, Veljko (ur.).
Rijeka: Hrvatska udruga za informacijsku i komunikacijsku tehnologiju, elektroniku i mikroelektroniku - MIPRO, 2008. str. 75-78 (predavanje, međunarodna recenzija, cjeloviti rad (in extenso), znanstveni)
CROSBI ID: 359316 Za ispravke kontaktirajte CROSBI podršku putem web obrasca
Naslov
Detecting Vulnerabilities in Web Applications by Clustering Web Pages
Autori
Suhina, Vanja ; Groš, Stjepan ; Kalafatić, Zoran
Vrsta, podvrsta i kategorija rada
Radovi u zbornicima skupova, cjeloviti rad (in extenso), znanstveni
Izvornik
Proc. 31st Int'l Convention MIPRO 2008, Vol. V: Digital Economy - 5th ALADIN, Information Systems Security, Business Intelligence Systems, Local Government, Student Papers
/ Čišić, Dragan ; Hutinski, Željko ; Baranović, Mirtas ; Mauher, Mladen ; Dragšić, Veljko - Rijeka : Hrvatska udruga za informacijsku i komunikacijsku tehnologiju, elektroniku i mikroelektroniku - MIPRO, 2008, 75-78
ISBN
978-953-233-040-3
Skup
31st International Convention MIPRO 2008
Mjesto i datum
Opatija, Hrvatska, 26.05.2008. - 30.05.2008
Vrsta sudjelovanja
Predavanje
Vrsta recenzije
Međunarodna recenzija
Ključne riječi
data mining; fuzzing; security; unsupervised learning; vulnerability
Sažetak
In this paper, we propose a new approach to detecting vulnerabilities in Web applications. Majority of current Web application vulnerability scanners rely on detecting vulnerabilities by detecting common error messages or input vectors used in testing. The method we propose in this paper is based on detecting unusual behavior of a Web application. Differences between pages are analyzed by examining page structure, i.e. HTML elements. Variations from standard page structure could indicate raised errors in the Web application and could indicate a vulnerability. Issues that arise in building such a tool will be described here.
Izvorni jezik
Engleski
Znanstvena područja
Računarstvo
POVEZANOST RADA
Projekti:
036-0361994-1995 - Univerzalna posrednička platforma za sustave e-učenja (Glavinić, Vlado, MZO ) ( CroRIS)
Ustanove:
Fakultet elektrotehnike i računarstva, Zagreb