dc.contributor | Pastor Ramírez, Danilo | |
dc.contributor | Arcos Medina, Gloria | |
dc.contributor | Haro Mendoza, Daniel | |
dc.creator | Paguay Soxo, Paúl Xavier | |
dc.date.accessioned | 2015-08-07T20:37:04Z | |
dc.date.available | 2015-08-07T20:37:04Z | |
dc.date.created | 2015-08-07T20:37:04Z | |
dc.date.issued | 2013-03 | |
dc.identifier | Paguay Soxo, Paúl Xavier. (2013). Propuesta de técnicas de aseguramiento de aplicaciones web desarrolladas en Java. Escuela Superior Politécnica de Chimborazo. Riobamba. | |
dc.identifier | http://dspace.espoch.edu.ec/handle/123456789/4029 | |
dc.description.abstract | This work aims to establish technical proposals to assure Web appl
ications
developed in JAVA mainly with JSP technology applied to the Web site of the
Graduate and Continuing Education School
-
ESPOCH.
The established techniques were applied to a production system such as the
System Administrative Academic EPEC
-
SISEPE
C, finding 2 stages Web to
work on. One was implemented with such techniques and other without any
technique. It was analyzed with the same service, the automation of the
processes of the department. In each scenario, it was evaluated the
vulnerabilities b
y category, such as Confidentiality, Integrity and Availability
(CID), which are indicators of the safety of a Web system.
To analyze the vulnerability, scanning tools based on free software were used.
These software are the same used by hacker communitie
s worldwide such as
the suites Backtrack and OSSIM.
After collection and tabulation of data it was found that the techniques
implemented application decreases the number of vulnerabilities in all
categories of the CID, which it improved the Web site secur
ity by 41.06%
compared to not implementing techniques.
As a conclusion, the system security Web was improved.
Afterwards a security
guide for securing source code of future implementations JAVA
-
JSP on the
Web was done.
It is recommended that assurance
techniques must be considered and
implemented in full. Also the constant updating of new vulnerabilities is
necessary for this type of Web systems. | |
dc.language | spa | |
dc.publisher | Escuela Superior Politécnica de Chimborazo | |
dc.relation | UDCTEPEC;20T00467 | |
dc.rights | https://creativecommons.org/licenses/by-nc-sa/3.0/ec/ | |
dc.rights | info:eu-repo/semantics/openAccess | |
dc.subject | APLICACIONES WEB | |
dc.subject | ASEGURAMIENTO DE APLICACIONES WEB | |
dc.subject | DESARROLLO DE APLICACIONES WEB | |
dc.subject | JAVA | |
dc.subject | SISTEMAS WEB | |
dc.subject | TÉCNICAS DE ASEGURAMIENTO DE APLICACIONES WEB | |
dc.subject | VULNERABILIDAD | |
dc.title | Propuesta de técnicas de aseguramiento de aplicaciones web desarrolladas en Java. | |
dc.type | info:eu-repo/semantics/masterThesis | |