A Study of Various Approaches to Assess and Provide Web based Application Security

Dhanya Pramod · 2011

World Wide Web has grown in leaps and bounds and provides a promising platform for hosting applications. The web applications are developed without being taking care the criticality of security aspects and thus prone to attacks. The various efforts made by researchers and open forums would help to develop secure web application development, deployment and maintenance. This paper brings forth various aspects and work done to incorporate security in web based applications. An overview of security assessment methods is also included. Index Terms—webapplications; security; vulnerability, attacks I. I NTRODUCTION Web applications are always available on the internet and accessible any time. The vulnerabilities present in the application can be exploited by an attacker to abuse the functionality of the application or leak the data associated with it. There are several well known attack techniques to penetrate the web applications. There have been tremendous research efforts in this field to identify and plug these security vulnerabilities. The best known efforts, methods and tools to deal with security issues have been discussed in this paper. Web Application security Consortium (WASC) (28) gives an open platform for security professionals, academia, software developers, software vendors and system auditors to access the latest security issues and countermeasures. The web application security project that can be accessed online contributes to develop and promote industry standard terminology for describing the issues. The efforts of the consortium bring forth the attacks and create awareness of the same among various stake holder communities. It also classifies various types of attacks using a cooperative effort and publishes as Web Security Threat Classification. The WASC also facilitates documentation of the details of each class of attack and give a name to each class of attack. It also provides a structured way to organize the classes of attack. WASC is the leading contributor of dissemination of security related issues and takes efforts to provide a consistent language to the same. According to the survey conducted by WASC following are the cause for critical web hacking incidents. Improper Output Handling, Insufficient Anti-Automation, Improper Input Handling, Insufficient

Read the paper · More papers on PaperTik