{"title":"New Attack Potential Measurement Method to Kaizen Event for Web Application Security Vulnerabilities","authors":"Kuo-Sui Lin","doi":"10.7903/ijecs.1536","DOIUrl":null,"url":null,"abstract":"With recognition of the importance of web application security, there is a need for research on an action program for measurement and improvement of web application security. Therefore, the main purpose of this study was to formulate a Kaizen program suitable for measurement and improvement of web application security vulnerabilities. An improvement working procedure is introduced to implement the Kaizen program. Further, an augmented attack potential measurement method is proposed to measure the effectiveness of the formulated Kaizen program. The proposed new attack potential measurement method is considered to be an umbrella under which several novel techniques and methods are included, such as OWASP’s web application security vulnerabilities assessment method, ISO/IEC 18045 attack potential ratings method and fuzzy evaluation method. The numerical results of an example are presented to show that the augmented attack potential measurement method is not only comparable but also distinguishable. It is more reasonable and effective than that of the traditional method for measuring web application security improvement. Finally, conclusions are made and suggestions for future work are proposed. To cite this document: Kuo-Sui Lin, \"New Attack Potential Measurement Method to Kaizen Event for Web Application Security Vulnerabilities\", International Journal of Electronic Commerce Studies, Vol.10, No.2, pp.89-112, 2019. Permanent link to this document: http://dx.doi.org/10.7903/ijecs.1536","PeriodicalId":38305,"journal":{"name":"International Journal of Electronic Commerce Studies","volume":" ","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2019-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Electronic Commerce Studies","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.7903/ijecs.1536","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"Computer Science","Score":null,"Total":0}
引用次数: 1
Abstract
With recognition of the importance of web application security, there is a need for research on an action program for measurement and improvement of web application security. Therefore, the main purpose of this study was to formulate a Kaizen program suitable for measurement and improvement of web application security vulnerabilities. An improvement working procedure is introduced to implement the Kaizen program. Further, an augmented attack potential measurement method is proposed to measure the effectiveness of the formulated Kaizen program. The proposed new attack potential measurement method is considered to be an umbrella under which several novel techniques and methods are included, such as OWASP’s web application security vulnerabilities assessment method, ISO/IEC 18045 attack potential ratings method and fuzzy evaluation method. The numerical results of an example are presented to show that the augmented attack potential measurement method is not only comparable but also distinguishable. It is more reasonable and effective than that of the traditional method for measuring web application security improvement. Finally, conclusions are made and suggestions for future work are proposed. To cite this document: Kuo-Sui Lin, "New Attack Potential Measurement Method to Kaizen Event for Web Application Security Vulnerabilities", International Journal of Electronic Commerce Studies, Vol.10, No.2, pp.89-112, 2019. Permanent link to this document: http://dx.doi.org/10.7903/ijecs.1536
期刊介绍:
The IJECS is a double-blind referred academic journal for all fields of Electronic Commerce. To serve as an international platform, the IJECS encourages manuscript submissions from authors all around the world. As a multi-discipline journal, The IJECS welcome both technology oriented and business oriented electronic commerce research articles. The purpose of the International Journal of Electronic Commerce Studies is to promote electronic commerce research and provide worldwide scholars a place to publish their innovative work in electronic commerce. To be published in the journal, the manuscript must make strong empirical, theoretical, or practical contributions and highlight the significance of the contributions to the electronic commerce field. Thus, preference is given to submissions that test, extend, or build strong theoretical frameworks for electronic commerce theory, electronic commerce system development, and electronic commerce practice. The journal is not tied to any particular national context; the geographic distribution of authors publishing in the journal came from countries around the world. Articles introducing cases of innovative applications in electronic commerce around the world are also published in the journal. The journal provides scholars opportunities to realize the electronic commerce research and development around the world. Articles in the International Journal of Electronic Commerce Studies will include, but are not limited to the following areas.