Worst-Input Mutation Approach to Web Services Vulnerability Testing Based on SOAP Messages

来源 :Tsinghua Science and Technology | 被引量 : 0次 | 上传用户:Jordan2391
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
The growing popularity and application of Web services have led to increased attention regarding the vulnerability of software based on these services.Vulnerability testing examines the trustworthiness and reduces the security risks of software systems.This paper proposes a worst-input mutation approach for testing Web service vulnerability based on Simple Object Access Protocol(SOAP)messages.Based on characteristics of SOAP messages,the proposed approach uses the farthest neighbor concept to guide generation of the test suite.The corresponding automatic test case generation algorithm,namely,the Test Case generation based on the Farthest Neighbor(TCFN),is also presented.The method involves partitioning the input domain into sub-domains according to the number and type of SOAP message parameters in the TCFN,selecting the candidate test case whose distance is the farthest from all executed test cases,and applying it to test the Web service.We also implement and describe a prototype Web service vulnerability testing tool.The tool was applied to the testing of Web services on the Internet.The experimental results show that the proposed approach can find more vulnerability faults than other related approaches. The growing popularity and application of Web services have led to increased attention regarding the vulnerability of software based on these services. Vulnerability testing examines the trustworthiness and reduces the security risks of software systems. This paper proposes a worst-input mutation approach for testing Web services based on Simple Object Access Protocol (SOAP) messages. Based on characteristics of SOAP messages, the proposed approach uses the farthest neighbor concept to guide generation of the test suite. the corresponding automatic test case generation algorithm, namely, the Test Case Generation Based on the Farthest Neighbor (TCFN), is also presented. The method involves partitioning the input domain into sub-domains according to the number and type of SOAP message parameters in the TCFN, selecting the candidate test case whose distance is the farthest from all executed test cases, and apply it to test the Web service.We also implement and describe a prototype Web s ervice vulnerability testing tool. the tool was applied to the testing of web services on the Internet. the experimental results show that the proposed approach can find more vulnerability faults than other related approaches.
其他文献
俄罗斯港口发展战略的宏伟目标是,推进港口基础设施的现代化发展,不仅实现吞吐量的增长,而且要将贸易重心转向太平洋和南美国家。
滚滚销售东逝水,资本淘尽英雄.是非成败转头空,库存依旧在,几度夕阳红.新机二手江渚上,惯看营销风云.他年相遇再相逢,多少行业事,都付笑谈中.
期刊
2015年6月16日至2015年7月15日,中国质量万里行投诉部共收到投诉3950例,除了网络服务、IT通讯、房产家居、服装美容等行业的投诉量出现增长以外,汽车行业、旅游教育、金融保险、
Accell集团于日前宣布了René Takens(身兼CEO及董事会主席)离职的消息,该决定是经双方同意作出的.Takens将在2017年4月25日的下一次股东大会上辞去CEO的职务.rnRené Takens
期刊
印度港口的供需情况为投资者创造了良好的中、长期投资机会。尽管有体制弊端和官僚作风导致的项目延误,港口货物吞吐量仍有明显增长。
期刊
ID-based constant-round group key agreement protocols are efficient in both computation and communication,but previous protocols did not provide valid message a
在秋风送爽,丹桂飘香的九月,千里陇原处处充满丰收之景、洋溢着喜悦之情.在这美好的季节里,甘肃省地矿局迎来建局五十周年华诞.为此温家宝总理亲笔题写了“辉煌五十年”题词.
第一条 为贯彻《国务院关于加强土地调控有关问题的通知》(国发[2006]31号)精神,深化土地使用制度改革,规范工业用地招标拍卖挂牌出让行为,根据土地管理有关法律法规和政策规