dc.creatorSalas
dc.creatorM. I. P.; Martins
dc.creatorE.
dc.date2015-MAR
dc.date2016-06-07T13:17:00Z
dc.date2016-06-07T13:17:00Z
dc.date.accessioned2018-03-29T01:37:36Z
dc.date.available2018-03-29T01:37:36Z
dc.identifier
dc.identifierA Black-box Approach To Detect Vulnerabilities In Web Services Using Penetration Testing. Ieee-inst Electrical Electronics Engineers Inc, v. 13, p. 707-712 MAR-2015.
dc.identifier1548-0992
dc.identifierWOS:000352090200021
dc.identifier
dc.identifierhttp://ieeexplore.ieee.org/xpl/articleDetails.jsp?arnumber=7069095&newsearch=true&queryText=A%20Black-Box%20Approach%20to%20Detect%20Vulnerabilities%20in%20Web%20Services%20Using%20Penetration%20Testing
dc.identifierhttp://repositorio.unicamp.br/jspui/handle/REPOSIP/242227
dc.identifier.urihttp://repositorioslatinoamericanos.uchile.cl/handle/2250/1305925
dc.descriptionWeb services work over dynamic connections among distributed systems. This technology was specifically designed to easily pass SOAP message through firewalls using open ports. These benefits involve a number of security challenges, such as Injection Attacks, phishing, Denial-of-Services (DoS) attacks, and so on. The difficulty to detect vulnerabilities -before they are exploited- encourages developers to use security testing like penetration testing to reduce the potential attacks. Given a black-box approach, this research use the penetration testing to emulate a series of attacks, such as Cross-site Scripting (XSS), Fuzzing Scan, Invalid Types, Malformed XML, SQL Injection, XPath Injection and XML Bomb. In this way, was used the soapUI vulnerability scanner in order to emulate these attacks and insert malicious scripts in the requests of the web services tested. Furthermore, was developed a set of rules to analyze the responses in order to reduce false positives and negatives. The results suggest that 97.1% of web services have at least one vulnerability of these attacks. We also determined a ranking of these attacks against web services.
dc.description13
dc.description3
dc.description
dc.description707
dc.description712
dc.description
dc.description
dc.description
dc.languagept
dc.publisherIEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
dc.publisher
dc.publisherPISCATAWAY
dc.relationIEEE LATIN AMERICA TRANSACTIONS
dc.rightsfechado
dc.sourceWOS
dc.subjectComputer Science, Information Systems
dc.subjectEngineering, Electrical & Electronic
dc.titleA Black-box Approach To Detect Vulnerabilities In Web Services Using Penetration Testing
dc.typeArtículos de revistas


Este ítem pertenece a la siguiente institución