论文标题

部分可观测时空混沌系统的无模型预测

Evaluation of Static Analysis on Web Applications

论文作者

Ehichoya, Osejobe, Nnaemeka, Chinwuba Christian

论文摘要

Web服务正在成为关键业务组件,通常由可以恶意探索的关键软件错误部署。 Web漏洞扫描仪可以通过从攻击者的角度强调服务来检测Web服务中的安全漏洞。但是,研究和实践表明,不同的扫描仪在脆弱性检测中的表现不同。本文介绍了对Web应用程序中发现的安全漏洞的定性评估。一些众所周知的漏洞扫描仪已被用来识别Web服务实现中的安全缺陷。已经观察到许多漏洞,这些漏洞证实了许多服务在没有适当安全测试的情况下被部署。此外,在审查并考虑了几篇文章后,检测到的漏洞的差异以及观察到的大量误报数量突出了Web漏洞扫描仪在检测Web服务中的安全漏洞时的局限性。此外,这项工作将讨论在Web应用程序中发现安全漏洞的静态分析方法,并为其提供了可靠的研究发现或解决方案。这些漏洞包括损坏的访问控制,跨站点脚本,SQL注入,缓冲区溢出,无限制的文件上传,损坏的身份验证等。Web应用程序正在成为企业的任务成分组件,可能会冒着有几种软件漏洞可能会造成恶意剥削的软件漏洞。已经使用了一些漏洞扫描仪来检测Web服务应用程序中的安全弱点,并且已经发现了许多漏洞,因此证实了许多在没有足够安全测试的没有足够的安全性测试的在线应用程序。

Web services are becoming business-critical components, often deployed with critical software bugs that can be maliciously explored. Web vulnerability scanners allow the detection of security vulnerabilities in web services by stressing the service from the point of view of an attacker. However, research and practice show that different scanners perform differently in vulnerability detection. This paper presents a qualitative evaluation of security vulnerabilities found in web applications. Some well-known vulnerability scanners have been used to identify security flaws in web service implementations. Many vulnerabilities have been observed, which confirms that many services are deployed without proper security testing. Additionally, having reviewed and considered several articles, the differences in the vulnerabilities detected and the high number of false positives observed highlight the limitations of web vulnerability scanners in detecting security vulnerabilities in web services. Furthermore, this work will discuss the static analysis approach for discovering security vulnerabilities in web applications and complimenting it with proven research findings or solutions. These vulnerabilities include broken access control, cross-site scripting, SQL injections, buffer overflow, unrestricted file upload, broken authentications, etc. Web applications are becoming mission-essential components for businesses, potentially risking having several software vulnerabilities that hackers can exploit maliciously. A few Vulnerability scanners have been used to detect security weaknesses in web service applications, and many vulnerabilities have been discovered, thus confirming that many online apps are launched without sufficient security testing.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源