首页 | 本学科首页   官方微博 | 高级检索  
     

基于改进模糊测试的Web应用漏洞挖掘方法
引用本文:达小文,王晓程,陈志浩.基于改进模糊测试的Web应用漏洞挖掘方法[J].计算机与现代化,2016,0(8):100-96.
作者姓名:达小文  王晓程  陈志浩
摘    要:为解决Web模糊测试挖掘漏洞速度较慢、发现漏洞数较少的问题,提出一种改进的Web模糊测试向量生成方法。在通用的Web应用模糊测试结构(Web Fuzzing)基础上,分析现有测试向量生成方法,引入遗传算法来改进Web模糊测试向量生成方法。基于该方法实现XSS模糊测试工具,使用该工具对2个Web应用系统进行测试,将结果与现有模糊测试工具测试结果对比,验证了使用该方法挖掘Web漏洞速度快,发现漏洞数更多,提高了漏洞挖掘效率。

关 键 词:Web安全  Web漏洞  模糊测试  遗传算法  测试向量  
收稿时间:2016-08-11

Web Application Vulnerabilities Mining Method Based on Improved Fuzzing
DA Xiao-wen,WANG Xiao-cheng,CHEN Zhi-hao.Web Application Vulnerabilities Mining Method Based on Improved Fuzzing[J].Computer and Modernization,2016,0(8):100-96.
Authors:DA Xiao-wen  WANG Xiao-cheng  CHEN Zhi-hao
Abstract:To solve the problems that slower speed and fewer number of vulnerabilities found of Web fuzzing for mining vulnerabilities, a method to improve the generation of vectors of Web fuzzing is proposed. On the basis of the structure of commonly-used fuzzing for Web application (Web fuzzing) and the analyses of the current methods of testing vectors generation, the genetic algorithm to improve testing vector generation of Web fuzzing is applied. Based on this method, a XSS fuzzing tool is implemented. The testing results of multiple Web applications with XSS fuzzing tool and that with current fuzzing tool are compared, which indicates that the efficiency of mining vulnerability is increased with the method.
Keywords:Web security  Web vulnerability  fuzzing  genetic algorithm  test vector  
点击此处可从《计算机与现代化》浏览原始摘要信息
点击此处可从《计算机与现代化》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号