期刊文献+

Web服务安全性测试技术研究 被引量:6

Research on the Web Services Security Testing Technology
下载PDF
导出
摘要 Web服务的应用越来越广泛,Web服务中的安全缺陷与漏洞也在不断增多,Web服务安全性问题日益突出。Web服务安全性测试是保证Web服务软件安全性、降低安全风险的重要手段。本文提出了一种Web服务安全性测试框架,论述了Web服务主要的安全功能需求、实现标准及实施安全功能测试的一般原理,并从攻击Web服务的角度对Web服务安全漏洞测试进行了系统介绍,分析了Web服务常见的安全漏洞及测试方法。 Web services are applied more and more widely. The security flaws and vulnerabilities in Web services are growing. Web services security have become increasingly prominent. Web services security testing is an important means to ensure Web services security and decrease security risks. This paper presents a Web services security testing framework, and investigates the main security function requirements and implementation standards of Web services. It also discusses the principle of implementing security function testing. From the perspective of Web services attacking, it discusses the Web services security vulnerability testing,and analyzes the test methods for the common vulnerabilities.
出处 《计算机工程与科学》 CSCD 2007年第10期11-13,28,共4页 Computer Engineering & Science
关键词 WEB服务 安全性测试 模式中毒 路由劫持 WSDL扫描 Web services security testing schema poisoning routing detours WSDL scanning
  • 相关文献

参考文献6

  • 1Chandramouli R, Blackburn M R. Automated Testing of Security Functions Using a Combined Model and Interface-Driven Approach[A]. Proc of HICSS[C]. 2004.
  • 2Kearney P. Message Level Security for Web Services[J]. Information Security Technical Report, 2005, (!0) : 41-50.
  • 3Desmet L, Jacobs B, Piessens F, et al. Threat Modelling for Web Services Based Web Applications[A]. Proc of the 8th IFIP TC-6 TC-ll Conf on Communications and Multimedia Security[C]. 2004.
  • 4Yu W D, Aravind D, Supthaweesuk P. Software Vulnerability Analysis for Web Services Software Systems[A]. Proc of the llth IEEE Int'l Symp on Computers and Communications [C]. 2006. 740-748.
  • 5Yunus M,Mallal R, An Empirical Study of Security Threats and Countermeasures in Web Services-Based Services Oriented Architectures[A]. Proc of the 6th Int'l Conf on Web Information Systems Engineering[C]. 2005. 653-659.
  • 6Lindstrom P. Attacking and Defending Web Services[EB/ OL]. http://forumsystems, corn/papers/Attacking_and Defending WS. pdf, 2004-01.

同被引文献24

引证文献6

二级引证文献13

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部