DocumentCode :
3515737
Title :
Using web security scanners to detect vulnerabilities in web services
Author :
Vieira, Marco ; Antunes, Nuno ; Madeira, Henrique
Author_Institution :
Dept. of Inf. Eng., Univ. of Coimbra, Coimbra, Portugal
fYear :
2009
fDate :
June 29 2009-July 2 2009
Firstpage :
566
Lastpage :
571
Abstract :
Although Web services are becoming business-critical components, they are often deployed with critical software bugs that can be maliciously explored. Web vulnerability scanners allow detecting security vulnerabilities in Web services by stressing the service from the point of view of an attacker. However, research and practice show that different scanners have different performance on vulnerabilities detection. In this paper we present an experimental evaluation of security vulnerabilities in 300 publicly available Web services. Four well known vulnerability scanners have been used to identify security flaws in Web services implementations. A large number of vulnerabilities has been observed, which confirms that many services are deployed without proper security testing. Additionally, the differences in the vulnerabilities detected and the high number of false-positives (35% and 40% in two cases) and low coverage (less than 20% for two of the scanners) observed highlight the limitations of Web vulnerability scanners on detecting security vulnerabilities in Web services.
Keywords :
Web services; program debugging; program diagnostics; program testing; security of data; Web security scanner; Web services; Web vulnerability scanner; attacker view; business-critical component; code vulnerability analysis; critical software bug; security flaw identification; security testing; security vulnerability detection; Application software; Databases; Informatics; Network servers; Security; Simple object access protocol; Testing; Web server; Web services; XML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems & Networks, 2009. DSN '09. IEEE/IFIP International Conference on
Conference_Location :
Lisbon
Print_ISBN :
978-1-4244-4422-9
Electronic_ISBN :
978-1-4244-4421-2
Type :
conf
DOI :
10.1109/DSN.2009.5270294
Filename :
5270294
Link To Document :
بازگشت