Please use this identifier to cite or link to this item:
https://www.um.edu.mt/library/oar/handle/123456789/92277| Title: | Testing a web application for security using static code analysis and dynamic analysis |
| Authors: | Sant, Lindsay (2008) |
| Keywords: | Computer security Hacking Number theory |
| Issue Date: | 2008 |
| Citation: | Sant, L. (2008). Testing a web application for security using static code analysis and dynamic analysis (Bachelor's dissertation). |
| Abstract: | Web application nowadays can perform very complex tasks and are therefore being used extensively to carry out many important tasks, processing millions of Euros in online transactions. Due to the fact that web applications are hosted on servers, which can be accessed by anyone, everywhere, this makes them continuously susceptible to attacks by malicious users. This is combined with the power of modem search engines, which can be used even by teenagers to learn how to attack systems. This should not be undermined, since a single vulnerability can completely wipe off a whole system completely. This highlights the importance of appropriately testing web applications for security. Our system is a flexible and extensible tool which uses a combination of static and dynamic analysis to identify security vulnerabilities. The framework also supports correlation of results from multiple static analysers. Any static analyser which can output the intra-procedural dataflow of the system being tested and output results in XML format can be plugged into our tool. This XML file is then transformed into a standard XML file accepted by the dynamic analyser implemented in our tool. The dynamic analyser uses the details from the output of the static analyser to generate attack strings specific to those issues. The generated test script is then submitted to the hosted system and the results are output to the user. From the test cases tried, the number of security vulnerabilities identified by the static analyser were reduced. Thus the developers would have less security vulnerabilities to check manually, thus saving them a lot of time especially in large projects. The implemented system provides a decent proof-of-concept, which can be later extended and improved. |
| Description: | B.Sc. IT (Hons)(Melit.) |
| URI: | https://www.um.edu.mt/library/oar/handle/123456789/92277 |
| Appears in Collections: | Dissertations - FacICT - 1999-2009 Dissertations - FacICTCS - 2008 |
Files in This Item:
| File | Description | Size | Format | |
|---|---|---|---|---|
| B.SC.(HONS)IT_Sant_Lindsay_2008.pdf Restricted Access | 19.21 MB | Adobe PDF | View/Open Request a copy |
Items in OAR@UM are protected by copyright, with all rights reserved, unless otherwise indicated.
