Towards benchmarking the trustworthiness of web applications code

Afonso Araújo Neto, Marco Paulo Amorim Vieira · 2011

Comparing the security of web applications is very hard and, although there are many proposals of security metrics in the literature, no consensual quantitative security metric has been proposed so far. In this paper we study the use of trust-based metrics as an alternative for benchmarking the security of web applications code. The approach consists of quantifying and exposing evidences that show that developers applied valuable best practices to prevent potential security vulnerabilities, thus improving the trustworthiness that can be justifiably put in the application. The idea is that the metrics should portray the relative level of trust users can put in an application regarding its ability to prevent attacks. To demonstrate the idea we conducted a preliminary experimental evaluation using two implementations of a complex Web Service. Although further research is needed, preliminary results suggest that trust-based metrics are a promising approach to compare web applications in terms of security features.

Read the paper · More papers on PaperTik