DocumentCode :
116047
Title :
Webservice based vulnerability testing framework
Author :
Selvam, R. ; Senthilkumar, A.
Author_Institution :
R&D Centre, Bharathiar Univ., Coimbatore, India
fYear :
2014
fDate :
6-8 March 2014
Firstpage :
1
Lastpage :
6
Abstract :
Software security is no longer just a problem for software designers, developers and testers. Almost all the white-collar crimes are based on computer security. Many research papers are published on static code analysis, dynamic code analysis and software development design time security issues. This paper proposes a framework for testing security vulnerabilities based on publicly known security vulnerabilities database. After vulnerabilities are found in application, the security tester uses Penetration testing tools to test the security flow. The Vulnerability Orchestration framework gets the vulnerability priority from the VulnerabilityTracker webservice. The Webservice collects the vulnerability attacks from the security Vulnerabilities database and update test case priority signature in the web service. The framework runs the test cases based on VulnerabilityTracker web service as part of the build process and execute security test suites for every build. The security tester adds the new test cases whenever they find a new vulnerability.
Keywords :
Web services; program diagnostics; program testing; security of data; VulnerabilityTracker Web service; Web service based vulnerability testing framework; computer security; dynamic code analysis; penetration testing tools; software designers; software developers; software development design time security issues; software security; software testers; static code analysis; vulnerabilities database; vulnerability orchestration framework; white-collar crimes; Database systems; Real-time systems; Security; Software; Testing; Unified modeling language; Vulnerability Orchestration framework; VulnerabilityTracker; framework; real time; security testing; webservice;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Green Computing Communication and Electrical Engineering (ICGCCEE), 2014 International Conference on
Conference_Location :
Coimbatore
Type :
conf
DOI :
10.1109/ICGCCEE.2014.6921391
Filename :
6921391
Link To Document :
بازگشت