• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Quantifying the attack surface of a web application
 
  • Details
  • Full
Options
2010
Conference Paper
Title

Quantifying the attack surface of a web application

Abstract
The attack surface of a system represents the exposure of application ob- jects to attackers and is affected primarily by architecture and design decisions. Given otherwise consistent conditions, reducing the attack surface of a system or an application is expected to reduce its overall vulnerability. So far, only systems have been considered but not single applications. As web applications provide a large set of applications built upon a common set of concepts and technologies, we choose them as an example, and provide qualitative and quantitative indicators. We propose a multidimensional metric for the attack surface of web applications, and discuss the rationale behind. Our metric is easy to use. It comprises both a scalar numeric indicator for easy comparison and a more detailed vector representation for deeper analysis. The metric can be used to guide security testing and development. We validate the applicability and suitability of the metric with popular web applications, of which knowledge about their vulnerability already exists.
Author(s)
Heumann, T.
Keller, J.
Türpe, S.
Mainwork
Sicherheit 2010. Sicherheit, Schutz und Zuverlässigkeit  
Conference
Gesellschaft für Informatik, Fachbereich Sicherheit (Jahrestagung) 2010  
File(s)
Download (189.33 KB)
Rights
Use according to copyright law
DOI
10.24406/publica-fhg-367184
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Keyword(s)
  • security metric

  • vulnerability

  • application security

  • security evaluation

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024