首页> 外文会议>2010 IEEE International Conference on Progress in Informatics and Computing >A resource-based approach to formalize use case specification for web applications
【24h】

A resource-based approach to formalize use case specification for web applications

机译:一种基于资源的方法来规范Web应用程序的用例规范

获取原文

摘要

Web applications under attack may perform undesirable behaviors against their use case specification. These attacks exploit web vulnerabilities which are usually considered as consequences of abusing web resources. The paper proposes a resource-based approach to formalize use case specification for web applications. The goal of the research is to identify and organize web resources, and to integrate web resources into use cases in a structured way. First, we filter web resource information based on the lexical analysis of the original use case specification. Then, we identify hidden web resources that are not listed in the event flow but required during the realization of the event. After that, we organize these web resources into a web resource tree. Finally, the formalized use case specification is constructed into a tree structure along with a defined event flow grammar. The resource-based use case specification enables security analysts to analyze the web vulnerabilities in terms of the resources required by each event. It is helpful to elicit security requirements.
机译:受攻击的Web应用程序可能会违反其用例规范。这些攻击利用了Web漏洞,通常将其视为滥用Web资源的后果。本文提出了一种基于资源的方法来规范Web应用程序的用例规范。研究的目的是识别和组织Web资源,并以结构化的方式将Web资源集成到用例中。首先,我们基于原始用例规范的词法分析来过滤Web资源信息。然后,我们确定事件流程中未列出但在事件实现期间必需的隐藏的Web资源。之后,我们将这些Web资源组织到Web资源树中。最后,形式化的用例规范与定义的事件流语法一起被构建为树结构。基于资源的用例规范使安全分析人员可以根据每个事件所需的资源来分析Web漏洞。提出安全要求很有帮助。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号