2023
DOI: 10.1109/tse.2023.3256322
|View full text |Cite
|
Sign up to set email alerts
|

Metamorphic Testing for Web System Security

Abstract: Security testing aims at verifying that the software meets its security properties. In modern Web systems, however, this often entails the verification of the outputs generated when exercising the system with a very large set of inputs. Full automation is thus required to lower costs and increase the effectiveness of security testing. Unfortunately, to achieve such automation, in addition to strategies for automatically deriving test inputs, we need to address the oracle problem, which refers to the challenge,… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2

Citation Types

0
2
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 7 publications
(2 citation statements)
references
References 103 publications
0
2
0
Order By: Relevance
“…And the threat of SQLi and XSS attacks to modern websites, emphasizing their prevalence and potential  ISSN: 2088-8708 for serious damage. It presents an in-depth review of these attacks, their vulnerabilities, and prevention methods, while also discussing future countermeasure developments [16]- [18].…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…And the threat of SQLi and XSS attacks to modern websites, emphasizing their prevalence and potential  ISSN: 2088-8708 for serious damage. It presents an in-depth review of these attacks, their vulnerabilities, and prevention methods, while also discussing future countermeasure developments [16]- [18].…”
Section: Related Workmentioning
confidence: 99%
“…Metamorphic security testing for web-interactions (MST-wi) automates security testing in modern web systems, addressing the oracle problem by integrating input generation strategies and utilizing engineerspecified metamorphic relations. Evaluation on Jenkins and Joomla revealed an 85% detection rate for vulnerabilities, highlighting MST-wi's scalability and efficacy in automated web system security testing [18]. An overview of vulnerability assessment and penetration testing (VAPT) techniques to address the increasing web hacking activities and emphasizes the importance of cybersecurity awareness and measures for organizations to protect against cyber threats [19]- [21].…”
Section: Related Workmentioning
confidence: 99%