The Method of Generating Web Link Security Testing Scenario Based on UML Diagram
Shuyan Wang, Jiaze Sun, Ju Zhang · 2016
Targeting the security vulnerabilities of unauthorized access caused by the failed link restriction and session authentication in Web application, a new method of generating Web link safety testing scenario based on UML diagram was proposed. Firstly, this method constructs the UML extended state diagram with the combination of the jump relationship of Web pages and user operation permission, Then it generates the corresponding extended state tree. Each path in the extended state tree would be used as a main scenario for link testing, Finally, it divides the main scenario into different sub-scenarios according to the link edge type to achieve the comprehensive test of the safety of the Web link. According to experimental analysis, this test scenario generation can accurately and effectively achieve the safety testing of the Web software when it met the full coverage of the link edges. Experimental results show that the proposed method can be used to conduct comprehensive analysis and detection of the Web security vulnerabilities caused by failure in link restriction and session authentication, and it is helpful for the early detection of potential security risks in Web application software and for protecting the Web application from security threats.