Affiliation:
1. University of Alberta, Canada
Abstract
The results of an extensive investigation of cookie deployment amongst 100,000 Internet sites are presented. Cookie deployment is found to be approaching universal levels and hence there exists an associated need for relevant Web and software engineering processes, specifically testing strategies which actively consider cookies. The semi-automated investigation demonstrates that over two-thirds of the sites studied deploy cookies. The investigation specifically examines the use of first-party, third-party, sessional, and persistent cookies within Web-based applications, identifying the presence of a P3P policy and dynamic Web technologies as major predictors of cookie usage. The results are juxtaposed with the lack of testing strategies present in the literature. A number of real-world examples, including two case studies are presented, further accentuating the need for comprehensive testing strategies for Web-based applications. The use of antirandom test case generation is explored with respect to the testing issues discussed. Finally, a number of seeding vectors are presented, providing a basis for testing cookies within Web-based applications.
Publisher
Association for Computing Machinery (ACM)
Subject
Computer Networks and Communications
Reference62 articles.
1. ]]Alexa Internet Inc. 2006a. About the Alexa traffic rankings. http://www.alexa.com/site/devcorner/top_sites. ]]Alexa Internet Inc. 2006a. About the Alexa traffic rankings. http://www.alexa.com/site/devcorner/top_sites.
2. ]]Alexa Internet Inc. 2006b. Alexa top site service. http://www.alexa.com/site/devcorner/top_sites. ]]Alexa Internet Inc. 2006b. Alexa top site service. http://www.alexa.com/site/devcorner/top_sites.
3. Cookies on-the-move
4. Testing Web applications by modeling with FSMs
5. ]]Auger R. Currudo C. Huseby S. H. Newman A. C. Pompon R. Groves D. and Ristic I. 2005. Web security glossary. Web Application Security Consortium. http://www.webappsec.org/projects/glossary/. ]]Auger R. Currudo C. Huseby S. H. Newman A. C. Pompon R. Groves D. and Ristic I. 2005. Web security glossary. Web Application Security Consortium. http://www.webappsec.org/projects/glossary/.
Cited by
14 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献