Model-based penetration test framework for web applications using TTCN-3

7Citations
Citations of this article
17Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Penetration testing is a widely used method for testing the security of web applications, but it can be inefficient if it is not done systematically. Public databases of web application vulnerabilities can be used to drive penetration testing, but testers need to understand them and interpret them into executable test cases. This requires an in-depth knowledge of security. This paper proposes a model-based testing approach using a data model that describes the relationship between web security knowledge, business domain knowledge, and test case development. The approach consists of a data model that represents the relevance between attack surface, application fingerprint, attack vectors, and fuzz vectors; a test case generator that automatically generates penetration test scenarios for web applications; and a penetration test framework supported by TTCN-3 test environment. The model-based testing approach can be used to provide structured tool support for developing penetration test campaigns. We demonstrate the feasibility and efficiency of the approach at the design level. © 2009 Springer Berlin Heidelberg.

Cite

CITATION STYLE

APA

Xiong, P., Stepien, B., & Peyton, L. (2009). Model-based penetration test framework for web applications using TTCN-3. In Lecture Notes in Business Information Processing (Vol. 26 LNBIP, pp. 141–154). Springer Verlag. https://doi.org/10.1007/978-3-642-01187-0_12

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free