Please use this identifier to cite or link to this item: https://www.um.edu.mt/library/oar/handle/123456789/92277
Title: Testing a web application for security using static code analysis and dynamic analysis
Authors: Sant, Lindsay (2008)
Keywords: Computer security
Hacking
Number theory
Issue Date: 2008
Citation: Sant, L. (2008). Testing a web application for security using static code analysis and dynamic analysis (Bachelor's dissertation).
Abstract: Web application nowadays can perform very complex tasks and are therefore being used extensively to carry out many important tasks, processing millions of Euros in online transactions. Due to the fact that web applications are hosted on servers, which can be accessed by anyone, everywhere, this makes them continuously susceptible to attacks by malicious users. This is combined with the power of modem search engines, which can be used even by teenagers to learn how to attack systems. This should not be undermined, since a single vulnerability can completely wipe off a whole system completely. This highlights the importance of appropriately testing web applications for security. Our system is a flexible and extensible tool which uses a combination of static and dynamic analysis to identify security vulnerabilities. The framework also supports correlation of results from multiple static analysers. Any static analyser which can output the intra-procedural dataflow of the system being tested and output results in XML format can be plugged into our tool. This XML file is then transformed into a standard XML file accepted by the dynamic analyser implemented in our tool. The dynamic analyser uses the details from the output of the static analyser to generate attack strings specific to those issues. The generated test script is then submitted to the hosted system and the results are output to the user. From the test cases tried, the number of security vulnerabilities identified by the static analyser were reduced. Thus the developers would have less security vulnerabilities to check manually, thus saving them a lot of time especially in large projects. The implemented system provides a decent proof-of-concept, which can be later extended and improved.
Description: B.Sc. IT (Hons)(Melit.)
URI: https://www.um.edu.mt/library/oar/handle/123456789/92277
Appears in Collections:Dissertations - FacICT - 1999-2009
Dissertations - FacICTCS - 2008

Files in This Item:
File Description SizeFormat 
B.SC.(HONS)IT_Sant_Lindsay_2008.pdf
  Restricted Access
19.21 MBAdobe PDFView/Open Request a copy


Items in OAR@UM are protected by copyright, with all rights reserved, unless otherwise indicated.