Title :
Research and design on Web application vulnerability scanning service
Author :
Wu Qianqian ; Liu Xiangjun
Author_Institution :
Dept. of Inf. & Commun. Eng., North China Electr. Power Univ., Beijing, China
Abstract :
Web application has got a remarkable change in the past few years, many new technologies are reshaping the pattern of Web applications. Since many manufacturers´ promotion on HTML5 technology, more and more websites are using HTML5 gradually. The new technology provides users with a variety of Internet applications, but introduces new security problems at the same time. Currently, most Web application scanners can not detect the security problems with HTML5 features, which make HTML5 security issues become blind spots in security vulnerability scanning process. The paper focuses on a research among the existing Web application scanners firstly. Then we selected W3af(Web Application Attack and Audit Framework) as a basic platform for transformation, and by customizing scanning modules and scripts, we designed a Web application security scanning service. The practical scan results show that it can not only detect the Clickjacking vulnerabilities brought by HTML5, but also provide efficient Web application security scanning and evaluation services for the websites.
Keywords :
Web design; computer crime; hypermedia markup languages; Clickjacking vulnerabilities; HTML5 features; HTML5 security issues; HTML5 technology; Internet applications; W3af; Web application attack and audit framework; Web application scanners; Web application security vulnerability scanning service; Web sites; blind spots; evaluation services; scanning modules; scanning scripts; security problems; security vulnerability scanning process; Browsers; Educational institutions; Java; Power systems; Security; Testing; Web pages; Clickjacking; HTML5; W3af; Web application vulnerability scanning;
Conference_Titel :
Software Engineering and Service Science (ICSESS), 2014 5th IEEE International Conference on
Conference_Location :
Beijing
Print_ISBN :
978-1-4799-3278-8
DOI :
10.1109/ICSESS.2014.6933657