首页> 外文期刊>Journal of Computer and Communications >Systematic Review of Web Application Security Vulnerabilities Detection Methods
【24h】

Systematic Review of Web Application Security Vulnerabilities Detection Methods

机译:Web应用程序安全漏洞检测方法的系统综述

获取原文
           

摘要

In recent years, web security has been viewed in the context of securing the web application layer from attacks by unauthorized users. The vulnerabilities existing in the web application layer have been attributed either to using an inappropriate software development model to guide the development process, or the use of a software development model that does not consider security as a key factor. Therefore, this systematic literature review is conducted to investigate the various security vulnerabilities used to secure the web application layer, the security approaches or techniques used in the process, the stages in the software development in which the approaches or techniques are emphasized, and the tools and mechanisms used to detect vulnerabilities. The study extracted 519 publications from respectable scientific sources, i.e. the IEEE Computer Society, ACM Digital Library, Science Direct, Springer Link. After detailed review process, only 56 key primary studies were considered for this review based on defined inclusion and exclusion criteria. From the review, it appears that no one software is referred to as a standard or preferred software product for web application development. In our SLR, we have performed a deep analysis on web application security vulnerabilities detection methods which help us to identify the scope of SLR for comprehensively investigation in the future research. Further in this SLR considering OWASP Top 10 web application vulnerabilities discovered in 2012, we will attempt to categories the accessible vulnerabilities. OWASP is major source to construct and validate web security processes and standards.
机译:近年来,已经在保护Web应用程序层免受未授权用户攻击的上下文中查看了Web安全。 Web应用程序层中存在的漏洞归因于使用不合适的软件开发模型来指导开发过程,或者归因于使用不将安全性视为关键因素的软件开发模型。因此,进行了系统的文献综述,以调查用于保护Web应用程序层的各种安全漏洞,过程中使用的安全方法或技术,软件开发过程中强调这些方法或技术的阶段以及工具。以及用于检测漏洞的机制。该研究从受人尊敬的科学资源(即IEEE计算机协会,ACM数字图书馆,Science Direct,Springer Link)中提取了519种出版物。经过详细的审查过程,根据定义的纳入和排除标准,仅考虑了56项主要的主要研究。从评论来看,似乎没有一种软件被称为用于Web应用程序开发的标准或首选软件产品。在我们的SLR中,我们对Web应用程序安全漏洞检测方法进行了深入分析,这些方法可帮助我们确定SLR的范围,以便在以后的研究中进行全面调查。在此SLR中,考虑到OWASP在2012年发现的十大Web应用程序漏洞,我们还将尝试对可访问漏洞进行分类。 OWASP是构建和验证Web安全流程和标准的主要来源。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号