【24h】

Automatic fuzz testing of web service vulnerability

机译:Web服务漏洞的自动模糊测试

获取原文

摘要

With the wide application of service-oriented architecture and web service technology, the security requirements for web services is increasing. This paper presents a web services vulnerability identification and analysis method based on fuzz testing, including identifying inputs, generating fuzz testing data, performing fuzz testing, monitoring and identification of abnormal fragility, etc., thereby automatically identifies Web services architecture and performs fuzz testing. The low efficiency of abnormal data generation in web services fuzz testing is solved by using optimized grouping method, and the heavy work and inefficiency brought from manual testing can be avoided and the vulnerability of web services can be tested in depth. A web services vulnerability testing tool called WSFuzzer is implemented based on the proposed fuzz testing method, which implements the detection and analysis of web services vulnerabilities through the generation and execution of web services fuzz testing cases. Several vulnerabilities including SQL injection, information leakage, XPath injection are discovered by using WSFuzzer to carry out web services vulnerability fuzz testing, which shows that the proposed method can test web service vulnerabilities with high efficiency and accuracy.
机译:随着面向服务的体系结构和Web服务技术的广泛应用,Web服务的安全性要求日益提高。本文提出了一种基于模糊测试的Web服务漏洞识别与分析方法,包括识别输入,生成模糊测试数据,进行模糊测试,监视和识别异常脆弱性等,从而自动识别Web服务体系结构并进行模糊测试。通过优化分组方法解决了Web服务模糊测试中异常数据生成的低效率问题,避免了手工测试带来的繁重工作和低效率,可以对Web服务的脆弱性进行深入测试。基于所提出的模糊测试方法,实现了一种称为WSFuzzer的Web服务漏洞测试工具,该工具通过生成和执行Web服务模糊测试案例来实现对Web服务漏洞的检测和分析。利用WSFuzzer对Web服务漏洞进行模糊测试,发现SQL注入,信息泄漏,XPath注入等漏洞,表明该方法可以高效,准确地测试Web服务漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号