Management of the process of web applications testing by the fuzzing method based on dynamic Bayesov networks

Бесплатный доступ

Nowadays, intensive research is being conducted in the field of developing effective technologies for testing web applications for vulnerabilities, one of such technologies that allowing to hold complex testing at all stages of the application life cycle is fuzzing testing. The actual direction of development this technology is the development of mathematical and software that realizes intellectual components of fuzzing, the implementation of which will significantly improve its effectiveness and resource efficiency. In article the conceptual model of the application dynamic Bayesian networks to control web application testing by fuzzing is provided. Within the framework of the constructed conceptual model, dynamic Bayesian models for the main OWASP - vulnerability classes of Web applications and corresponding algorithmic and software for testing were developed.

Еще

Owasp - классы уязвимостей веб-приложений, owasp - classes of vulnerabilities of web applications, control of testing web applications, dynamic bayesian network, algorithms of training and a probable output

Короткий адрес: https://sciup.org/147155190

IDR: 147155190   |   DOI: 10.14529/ctcr170205

Статья научная