• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Supporting security testers in discovering injection flaws
 
  • Details
  • Full
Options
2008
Conference Paper
Title

Supporting security testers in discovering injection flaws

Abstract
We present a platform for software security testing primarily designed to support human testers in discovering injection flaws in distributed systems. Injection is an important class of security faults, caused by unsafe concatenation of input into strings interpreted by other components of the system. Examples include two of the most common security issues in Web applications, SQL injection and cross site scripting. This paper briefly discusses the fault model, derives a testing strategy that should discover a large subset of the injection flaws present, and describes a platform that helps security testers to discover injection flaws through dynamic grey-box testing. Our platform combines the respective strengths of machines and humans, automating what is easily automated while leaving to the tester the artistic portion of security testing. Although designed with a specific fault model in mind, our platform may be useful in a wide range of security testing tasks.
Author(s)
Türpe, S.
Poller, A.
Trukenmüller, J.
Repp, J.
Bornmann, C.
Mainwork
Testing: Academic and Industrial Conference. Practice and Research Techniques, TAIC PART 2008. Proceedings  
Conference
Testing - Academic and Industrial Conference 2008  
DOI
10.1109/TAIC-PART.2008.7
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Keyword(s)
  • security testing

  • tool

  • vulnerability

  • SQL injection

  • cross site scripting

  • Softwaretest

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024