对web应用程序威胁的系统回顾和分类

Yassine Sadqi, Yassine Maleh
{"title":"对web应用程序威胁的系统回顾和分类","authors":"Yassine Sadqi, Yassine Maleh","doi":"10.1080/19393555.2020.1853855","DOIUrl":null,"url":null,"abstract":"ABSTRACT Nowadays, web application security is one of the relevant issues in the IT security domain due to the continued growth in the number of web-related attacks. As a result, attacks, with various and varied motivations, have developed and become increasingly sophisticated. They mainly target data related to economic activities. Thus, they cause significant damage to the overall functioning of information systems. To address the various threats, several robust taxonomies exist in the literature. Each taxonomy and classification has advantages and limitations. We first define the different threat classifications related to the context of Web applications. The objective of this analysis is to provide a synthesis of the advantages and disadvantages of each classification. The current work analyses different taxonomies for web applications threats, in order to propose our proper taxonomy. The proposed taxonomy takes advantage of the benefits of existing taxonomies and provides an integrated approach for classifying both client-side and server-side attacks. The finding will help researchers to find a clear and detailed taxonomy of the different threats related to web applications.","PeriodicalId":103842,"journal":{"name":"Information Security Journal: A Global Perspective","volume":"47 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":"{\"title\":\"A systematic review and taxonomy of web applications threats\",\"authors\":\"Yassine Sadqi, Yassine Maleh\",\"doi\":\"10.1080/19393555.2020.1853855\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"ABSTRACT Nowadays, web application security is one of the relevant issues in the IT security domain due to the continued growth in the number of web-related attacks. As a result, attacks, with various and varied motivations, have developed and become increasingly sophisticated. They mainly target data related to economic activities. Thus, they cause significant damage to the overall functioning of information systems. To address the various threats, several robust taxonomies exist in the literature. Each taxonomy and classification has advantages and limitations. We first define the different threat classifications related to the context of Web applications. The objective of this analysis is to provide a synthesis of the advantages and disadvantages of each classification. The current work analyses different taxonomies for web applications threats, in order to propose our proper taxonomy. The proposed taxonomy takes advantage of the benefits of existing taxonomies and provides an integrated approach for classifying both client-side and server-side attacks. The finding will help researchers to find a clear and detailed taxonomy of the different threats related to web applications.\",\"PeriodicalId\":103842,\"journal\":{\"name\":\"Information Security Journal: A Global Perspective\",\"volume\":\"47 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-12-31\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"10\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Information Security Journal: A Global Perspective\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1080/19393555.2020.1853855\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Information Security Journal: A Global Perspective","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1080/19393555.2020.1853855","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

摘要

随着网络攻击的不断增加,web应用程序的安全成为IT安全领域的热点问题之一。因此,各种动机的攻击已经发展并变得越来越复杂。它们主要针对与经济活动有关的数据。因此,它们对信息系统的整体功能造成重大损害。为了应对各种威胁,文献中存在几种健壮的分类法。每种分类法和分类都有其优点和局限性。我们首先定义与Web应用程序上下文相关的不同威胁分类。本分析的目的是综合每种分类的优缺点。本文分析了web应用程序威胁的不同分类,以提出合适的分类方法。建议的分类法利用了现有分类法的优点,并提供了对客户端和服务器端攻击进行分类的集成方法。这一发现将帮助研究人员找到与网络应用程序相关的不同威胁的清晰而详细的分类。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A systematic review and taxonomy of web applications threats
ABSTRACT Nowadays, web application security is one of the relevant issues in the IT security domain due to the continued growth in the number of web-related attacks. As a result, attacks, with various and varied motivations, have developed and become increasingly sophisticated. They mainly target data related to economic activities. Thus, they cause significant damage to the overall functioning of information systems. To address the various threats, several robust taxonomies exist in the literature. Each taxonomy and classification has advantages and limitations. We first define the different threat classifications related to the context of Web applications. The objective of this analysis is to provide a synthesis of the advantages and disadvantages of each classification. The current work analyses different taxonomies for web applications threats, in order to propose our proper taxonomy. The proposed taxonomy takes advantage of the benefits of existing taxonomies and provides an integrated approach for classifying both client-side and server-side attacks. The finding will help researchers to find a clear and detailed taxonomy of the different threats related to web applications.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信