2012
DOI: 10.1007/978-3-642-34163-2_12
|View full text |Cite
|
Sign up to set email alerts
|

A Metamodel for Web Application Injection Attacks and Countermeasures

Abstract: Abstract. Web application injection attacks such as cross site scripting and SQL injection are common and problematic for enterprises. In order to defend against them, practitioners with large heterogeneous system architectures and limited resources struggle to understand the effectiveness of different countermeasures under various conditions. This paper presents an enterprise architecture metamodel that can be used by enterprise decision makers when deciding between different countermeasures for web applicati… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
7
0

Year Published

2013
2013
2023
2023

Publication Types

Select...
3
2

Relationship

3
2

Authors

Journals

citations
Cited by 6 publications
(7 citation statements)
references
References 27 publications
0
7
0
Order By: Relevance
“…A number of such countermeasures were identified during the pre-study [9], and we plan to study them utilizing the same approach as is presented in this paper.…”
Section: Discussionmentioning
confidence: 99%
See 2 more Smart Citations
“…A number of such countermeasures were identified during the pre-study [9], and we plan to study them utilizing the same approach as is presented in this paper.…”
Section: Discussionmentioning
confidence: 99%
“…Technical measures, process measures and organizational measures are all of relevance [8]. This study uses variables identified through a previous research [9] involving a literature review and expert judgment. This previous study is summarized in this section -the reader is referred to [9] for more comprehensive details.…”
Section: Model and Assumptionsmentioning
confidence: 99%
See 1 more Smart Citation
“…P 2 CySeMoL adds four important assets to the scope of Cy-SeMoL: SocialZone, NetworkVulnerabilityScanner [32], We-bApplication [33], [34] and WebApplicationFirewall [33], [35].…”
Section: Assets Attacks and Defensesmentioning
confidence: 99%
“…A WebApplication [33], [34] is a software written in a script language that is published by an HTTP server (an ApplicationServer). It is typically a combination of both server-side scripts (e.g., PHP) and client-side scripts (e.g., JavaScript).…”
Section: Assets Attacks and Defensesmentioning
confidence: 99%