شماره ركورد كنفرانس :
4705
عنوان مقاله :
BLProM: Business-layer Process Miner of the web application
پديدآورندگان :
Alidoosti Mitra Alidoosti@mut.ac.ir Malek-e-Ashtar University of technology , Nowroozi Alireza Nowroozi@ce.sharif.edu Sharif University of Technology
كليدواژه :
Business layer , Business process , Navigation graph
عنوان كنفرانس :
پانزدهمين كنفرانس بين المللي انجمن رمز ايران
چكيده فارسي :
Web application vulnerability scanners cannot detect business logic vulnerabilities (vulnerabilities related to logic) because they are not able to understand business logic of the web application. In order to identify business logic of the web application, this paper presents BLProM, the black box approach that identifies business processes of the web application. Detecting business processes of the web applications can be used in dynamic security testing to identify business logic vulnerabilities in the web applications. BLProM first extracts navigation graph of the web application then identifies business processes from the navigation graph. The evaluation conducted on three wellknown open source web applications shows that BLProM is able to detect business logic processes. Experimental results show that BLProM improves web application scanning because it clusters web application pages and prevent scanning similar pages. The proposed approach is compared to OWASP ZAP, an open source web scanner. We show that BLProM improves web application scanning about 96%