Vulnerability Coverage Criteria for Security Testing of Web Applications

PVR Murthy, R. G. Shilpa · 2018

Security and penetration testing tasks for web applications are important as they enable detection of vulnerabilities that attackers may exploit. Existing security coverage criteria or test adequacy criteria do not have a systematic basis. An attempt is made to define test adequacy criteria for web applications by abstracting a functional test as a sequence of events and mapping events to vulnerabilities as a basis for the design of security or penetration tests. Tests are designed primarily based on functional specifications of a web application, however, information about potential vulnerabilities at events may be gathered from different relevant sources including vulnerable regions of application code. A few interesting and effective security test adequacy criteria such as vulnerability-length-1, vulnerability-length-n and vulnerability pair-wise coverage are proposed as a basis for security test design or automatic test generation from models such as finite-state machines. The concepts are applied on a web application in the banking domain for demonstration purposes.

Read the paper · More papers on PaperTik