Automated and effective testing of web services for XML injection attacks

Author:

Jan Sadeeq1,Nguyen Cu D.1,Briand Lionel C.1

Affiliation:

1. University of Luxembourg, Luxembourg

Funder

Fonds National de la Recherche Luxembourg

Publisher

ACM

Reference35 articles.

1. OWASP. https : //www.owasp.org/index.php. Accessed: 2016-11-1. OWASP. https : //www.owasp.org/index.php. Accessed: 2016-11-1.

2. SmartBear ReadyAPI. http : //smartbear.com/product/ready − api/overview/. Accessed: 2015-11-18. SmartBear ReadyAPI. http : //smartbear.com/product/ready − api/overview/. Accessed: 2015-11-18.

3. SoapUI. http : //www.soapui.org/. Accessed: 2015-11-18. SoapUI. http : //www.soapui.org/. Accessed: 2015-11-18.

4. WS FUZZER Tool. https : //www.owasp.org/index.php/Category : OW ASP W SF uzzer P roject. Accessed: 2015-11-16. WS FUZZER Tool. https : //www.owasp.org/index.php/Category : OW ASP W SF uzzer P roject. Accessed: 2015-11-16.

5. XML Vulnerabilities Introduction. http: //resources.infosecinstitute.com/xml-vulnerabilities/. Accessed: 2014-06-22. XML Vulnerabilities Introduction. http: //resources.infosecinstitute.com/xml-vulnerabilities/. Accessed: 2014-06-22.

Cited by 9 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. URadar: Discovering Unrestricted File Upload Vulnerabilities via Adaptive Dynamic Testing;IEEE Transactions on Information Forensics and Security;2024

2. GeneMiner: A Classification Approach for Detection of XSS Attacks on Web Services;Computational Intelligence and Neuroscience;2022-06-25

3. An effective security assessment approach for Internet banking services via deep analysis of multimedia data;Multimedia Systems;2020-08-10

4. Revealing injection vulnerabilities by leveraging existing tests;Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering;2020-06-27

5. JCOMIX: a search-based tool to detect XML injection vulnerabilities in web applications;Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering;2019-08-12

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3