Pregled bibliografske jedinice broj: 427765
A method for identifying Web applications
A method for identifying Web applications // International Journal of Information Security, 8 (2009), 6; 455-467 doi:10.1007/s10207-009-0092-3 (međunarodna recenzija, članak, znanstveni)
CROSBI ID: 427765 Za ispravke kontaktirajte CROSBI podršku putem web obrasca
Naslov
A method for identifying Web applications
Autori
Kozina, Mario ; Golub, Marin ; Groš, Stjepan
Izvornik
International Journal of Information Security (1615-5262) 8
(2009), 6;
455-467
Vrsta, podvrsta i kategorija rada
Radovi u časopisima, članak, znanstveni
Ključne riječi
Web security; Web application identification; fingerprinting
Sažetak
Web applications are ubiquitous in today’ s businesses. The security of these applications is of utmost importance since security breaches might negatively impact good reputation, and even result in bankruptcy. There are different methods of assessing security of Web applications, mainly based on some automated method of scanning. One type of scan method feeds random data to the application and monitors its behavior. The other type uses a database with predefined vulnerabilities that are checked one by one until either a vulnerability is found, or it can be claimed that the application does not have any known vulnerabilities. The important step in the latter type of scan process is the identification of the application since in this case we are narrowing the number of checks and, as a consequence, the scan process is faster. This paper describes a method for Web application identification based on the black box principle. Our method is based on the invariance of certain characteristics of Web applications. We experimentally tested and confirmed the usefulness of this approach.
Izvorni jezik
Engleski
Znanstvena područja
Računarstvo
POVEZANOST RADA
Projekti:
036-0361994-1995 - Univerzalna posrednička platforma za sustave e-učenja (Glavinić, Vlado, MZO ) ( CroRIS)
036-0362980-1921 - Računalne okoline za sveprisutne raspodijeljene sustave (Srbljić, Siniša, MZO ) ( CroRIS)
Ustanove:
Fakultet elektrotehnike i računarstva, Zagreb
Citiraj ovu publikaciju:
Časopis indeksira:
- Current Contents Connect (CCC)
- Web of Science Core Collection (WoSCC)
- Science Citation Index Expanded (SCI-EXP)
- SCI-EXP, SSCI i/ili A&HCI
- Scopus