Research on web application security detecting system and key technologies
Ni Ding · Jisuanji gongcheng yu sheji · 2008
The design of the web application security detecting system is discussed in an open environment.The system consisted of the vulnerabilities library,web traverse,analysis engine,attack testing,secure auditing and auto-born report.The deep research is done on the key technologies of the system,including the library of the vulnerability characteristic,the acquisition of the website's topologic structure,the algorism of the tag parser and the attack testing,etc.A new model of web application vulnerabilities based on XML— WAML is proposed.The technology of the acquisition of the website's topologic structure in the traverse phase is also implemented.Eventually,the effective parts of the system are indicated by the results of a series of test and analysis those have been done on the im-plemented prototype system.