An Alternative Threat Model-based Approach for Security Testing

B. Falah, Mohammed Akour, Samia Oukemeni
{"title":"An Alternative Threat Model-based Approach for Security Testing","authors":"B. Falah, Mohammed Akour, Samia Oukemeni","doi":"10.4018/IJSSE.2015070103","DOIUrl":null,"url":null,"abstract":"In modern interaction, web applications has gained more and more popularity, which leads to a significate growth of exposure to malicious users and vulnerability attacks. This causes organizations and companies to lose valuable information and suffer from bad reputation. One of the effective mitigation practices is to perform security testing against the application before release it to the market. This solution won't protect web application 100% but it will test the application against malicious codes and reduce the high number of potential attacks on web application. One of known security testing approach is threat modeling, which provides an efficient technique to identify threats that can compromise system security. The authors proposed method, in this paper, focuses on improving the effectiveness of the categorization of threats by using Open 10 Web Application Security Project's OWASP that are the most critical web application security risks in generating threat trees in order to cover widely known security attacks.","PeriodicalId":89158,"journal":{"name":"International journal of secure software engineering","volume":"199 1","pages":"50-64"},"PeriodicalIF":0.0000,"publicationDate":"2015-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal of secure software engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/IJSSE.2015070103","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

In modern interaction, web applications has gained more and more popularity, which leads to a significate growth of exposure to malicious users and vulnerability attacks. This causes organizations and companies to lose valuable information and suffer from bad reputation. One of the effective mitigation practices is to perform security testing against the application before release it to the market. This solution won't protect web application 100% but it will test the application against malicious codes and reduce the high number of potential attacks on web application. One of known security testing approach is threat modeling, which provides an efficient technique to identify threats that can compromise system security. The authors proposed method, in this paper, focuses on improving the effectiveness of the categorization of threats by using Open 10 Web Application Security Project's OWASP that are the most critical web application security risks in generating threat trees in order to cover widely known security attacks.
一种基于威胁模型的安全测试方法
在现代交互中,web应用程序越来越受欢迎,这导致恶意用户暴露和漏洞攻击的显著增长。这会导致组织和公司失去有价值的信息,并遭受坏名声。有效的缓解实践之一是在将应用程序发布到市场之前对其执行安全测试。该解决方案不会100%保护web应用程序,但它将测试应用程序对恶意代码的攻击,并减少对web应用程序的大量潜在攻击。已知的安全测试方法之一是威胁建模,它提供了一种有效的技术来识别可能危及系统安全的威胁。在本文中,作者提出的方法侧重于通过使用Open 10 Web应用程序安全项目的OWASP来提高威胁分类的有效性,这些OWASP是生成威胁树中最关键的Web应用程序安全风险,以覆盖众所周知的安全攻击。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信