期刊文献+

一种新颖的Web服务安全性测试方法 被引量:1

A New Web Services Security Testing Method
下载PDF
导出
摘要 针对传统的Web服务安全性测试方法存在的低效、缺乏灵活性、不适应复杂安全功能测试及难以实现异常测试等问题,本文提出一种基于WSDL文件动态解析和安全功能分解的Web服务安全性测试方法。该方法采用运行时动态解析WSDL文件的方式解决了传统测试方法与被测Web服务紧耦合的问题,将复杂安全功能分解为7类原子安全处理类型,使其能够有效适应复杂安全功能测试的需要,采用故障注入机制生成错误的SOAP消息使其支持异常测试。实验结果表明,该方法具有灵活性、高效性和先进性。 The traditional Web services security testing methods are inefficient,inflexible and do not meet the complex security testing requirements and have difficulty in achieving negative testing. This paper presents a Web services security testing method based on dynamically parsing WSDLs and decomposing security functions. The method solves the problem that traditional testing methods are tightly coupled to the services under testing by dynamically parsing WSDLs. Complex security functions are divided into seven categories of atom security functions so that it can be adapted to complex security testing. It also uses a fault injection mechanism to generate error messages. The experimental results show that the method is flexible,efficient and advanced.
出处 《计算机工程与科学》 CSCD 北大核心 2010年第9期81-83,101,共4页 Computer Engineering & Science
基金 国家863计划资助项目(2009AA01Z146)
关键词 WEB服务 安全性测试 软件测试 Web service security testing software testing
  • 相关文献

参考文献4

二级参考文献16

  • 1Desmet L, Jacobs B, Piessens F, et al, Threat Modelling for Web Services Based Web Applications[C]//Proc. of the 8th IFIP TC-6 TC-11 Conference on Communications and Multimedia Security. NY, USA: [s. n.], 2004: 131-144.
  • 2Yu W D, Aravind D, Supthaweesuk E Software Vulnerability Analysis for Web Services Software Systems[C]//Proc. of the 11th IEEE International Symposium on Computers and Communications [S.l.]: IEEE Press, 2006: 740-748.
  • 3[1]Gary McCrraw,Bruee Potter.Soil-ware security testing[J].IEEE Security & Privacy,2004,2(5):81-85.
  • 4[2]David P Gilliam,John D Powell,Matt Bishop.Application of lightweight formal methods to software security[C].Linkoping,Sweden:Proc 14th IEEE International Workshops on Enabling Technologies,2005:160-165.
  • 5[4]Ramaswamy Chandramouli,Mark Blackburn.Automated testing of security functions using a combined model and interface-driven approach[C].Big Island,HI,USA:Proc 37th Hawaii Inter-national Conference on System Sciences,2004:5-8.
  • 6[5]Oded Tal,Scott Knight,Tom Dean.Syntax-based vulnerability testing of frame-based network protocols[C].Fredericton,New Brunswick,Canada:Proc Second Annual Conference on Privacy,Security and Trust,2004:155-160.
  • 7[6]Du Wenliang,Mathur A P.Vulnerability testing of software sys-tem using fault injection[R].Coast TR 98-02,1998.
  • 8[7]Du Wenliang,Aditya P Mathur.Testing for software vulnerability using environment perturbation[C].New York:Proc in Int Conf on Dependable Systems and Networks,2000:603-612.
  • 9[8]George Fink,Matt Bishop.Property based testing:A new approach to testing for assurance[J].ACM SIGSOFT Software Engineering Notes,1997,22(4):74-80.
  • 10Chandramouli R, Blackburn M R. Automated Testing of Security Functions Using a Combined Model and Interface-Driven Approach[A]. Proc of HICSS[C]. 2004.

共引文献25

同被引文献4

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部