@article{ART001636282},
author={Jaechan Moon and SEONG JE CHO},
title={Vulnerability Analysis and Threat Mitigation for Secure Web Application Development},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2012},
volume={17},
number={2},
pages={127-137}
TY - JOUR
AU - Jaechan Moon
AU - SEONG JE CHO
TI - Vulnerability Analysis and Threat Mitigation for Secure Web Application Development
JO - Journal of The Korea Society of Computer and Information
PY - 2012
VL - 17
IS - 2
PB - The Korean Society Of Computer And Information
SP - 127
EP - 137
SN - 1598-849X
AB - Recently, as modern Internet uses mashups, Web 3.0, JavaScript/AJAX widely, the rate at which new vulnerabilities are being discovered is increasing rapidly. It can subsequently introduce big security threats. In order to efficiently mitigate these web application vulnerabilities and security threats, it is needed to rank vulnerabilities based on severity and consider the severe vulnerabilities during a specific phase of software development lifecycle (SDLC) for web applications. In this paper, we have first verified whether the risk rating methodology of OWASP Top 10 vulnerabilities is a reasonable one or not by analyzing the vulnerability data of web applications in the US National Vulnerability Database (NVD). Then, by inspecting the vulnerability information of web applications based on OWASP Top-10 2010 list and CWE (Common Weakness Enumeration) directory, we have mapped the web-related entries of CWE onto the entries of OWASP Top-10 2010 and prioritized them. We have also presented which phase of SDLC is associated with each vulnerability entry. Using this approach, we can prevent or mitigate web application vulnerabilities and security threats efficiently.
KW - Web application;OWASP Top 10;Vulnerability analysis;Threat mitigation;Software development lifecycle (SDLC)
DO -
UR -
ER -
Jaechan Moon and SEONG JE CHO. (2012). Vulnerability Analysis and Threat Mitigation for Secure Web Application Development. Journal of The Korea Society of Computer and Information, 17(2), 127-137.
Jaechan Moon and SEONG JE CHO. 2012, "Vulnerability Analysis and Threat Mitigation for Secure Web Application Development", Journal of The Korea Society of Computer and Information, vol.17, no.2 pp.127-137.
Jaechan Moon, SEONG JE CHO "Vulnerability Analysis and Threat Mitigation for Secure Web Application Development" Journal of The Korea Society of Computer and Information 17.2 pp.127-137 (2012) : 127.
Jaechan Moon, SEONG JE CHO. Vulnerability Analysis and Threat Mitigation for Secure Web Application Development. 2012; 17(2), 127-137.
Jaechan Moon and SEONG JE CHO. "Vulnerability Analysis and Threat Mitigation for Secure Web Application Development" Journal of The Korea Society of Computer and Information 17, no.2 (2012) : 127-137.
Jaechan Moon; SEONG JE CHO. Vulnerability Analysis and Threat Mitigation for Secure Web Application Development. Journal of The Korea Society of Computer and Information, 17(2), 127-137.
Jaechan Moon; SEONG JE CHO. Vulnerability Analysis and Threat Mitigation for Secure Web Application Development. Journal of The Korea Society of Computer and Information. 2012; 17(2) 127-137.
Jaechan Moon, SEONG JE CHO. Vulnerability Analysis and Threat Mitigation for Secure Web Application Development. 2012; 17(2), 127-137.
Jaechan Moon and SEONG JE CHO. "Vulnerability Analysis and Threat Mitigation for Secure Web Application Development" Journal of The Korea Society of Computer and Information 17, no.2 (2012) : 127-137.