• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Towards continuous security certification of Software-as-a-Service applications using web application testing techniques
 
  • Details
  • Full
Options
2017
Conference Paper
Title

Towards continuous security certification of Software-as-a-Service applications using web application testing techniques

Abstract
Continuous security certification of software-asa- service (SaaS) aims at continuously, i.e. repeatedly and automatically validating whether a SaaS application adheres to a set of security requirements. Since SaaS applications make heavy use of web application technologies, checking security requirements with the help of web application testing techniques seems evident. However, these techniques mainly focus on conducting discrete security tests, that is, mostly manually triggered tests whose results are interpreted by human experts. Thus these techniques are not per se suited to support continuous security certification of SaaS applications and have to be adapted accordingly. In this paper, we report on our current status of developing methods and tools to support test-based, continuous security certification of SaaS applications which make use of web application testing techniques. To that end, we describe major challenges to overcome and present experimental test results of using SQLMap to continuously test for SQL injection vulnerabilities.
Author(s)
Stephanow, P.
Khajehmoogahi, K.
Mainwork
AINA 2017, 31st IEEE International Conference on Advanced Information Networking and Applications. Proceedings  
Project(s)
NGCert
EU-SEC  
Funder
Bundesministerium für Bildung und Forschung  
European Commission  
Conference
International Conference on Advanced Information Networking and Applications (AINA) 2017  
DOI
10.1109/AINA.2017.107
Language
English
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024