@article{ART002277533},
author={Jae-Ho Lee and Sang-Joon Lee},
title={Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size},
journal={Journal of Knowledge Information Technology and Systems},
issn={1975-7700},
year={2017},
volume={12},
number={5},
pages={747-763},
doi={10.34163/jkits.2017.12.5.015}
TY - JOUR
AU - Jae-Ho Lee
AU - Sang-Joon Lee
TI - Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size
JO - Journal of Knowledge Information Technology and Systems
PY - 2017
VL - 12
IS - 5
PB - Korea Knowledge Information Technology Society
SP - 747
EP - 763
SN - 1975-7700
AB - As the Web evolves, various web vulnerabilities are being discovered. Many companies and organizations are working to eliminate Web vulnerabilities, but they are not shrinking. Due to the nature of web vulnerability checks, dynamic checks are essential, and manual checks are preferred for accurate checking. In the case of a dynamic inspection performed manually, there are various problems such as false negative, missing inspection target and deflection due to inspectors. In this paper, we propose inspection methods and procedures to prevent a false negative, missing inspection target and deflection due to inspectors. In the proposed method, the web site is structured by Information Architecture(IA), and the detailed pages are classified into seven operation functions. The detailed pages are obtained by using the number of parameters, and the size of the entire website is calculated by adding the sizes of the detailed pages. Based on the number of Web vulnerability items to be used for the check, calculate the size of the page that can be checked in one day, and calculate the total inspection schedule. We verified the validity of the proposed method by comparing the number of vulnerabilities detected by the proposed method and the current method, and by analyzing the results of questionnaires for the related field workers. The proposed method can be applied not only to dynamic inspection but also to static inspection.
KW - Web application;Web vulnerability;Dynamic inspection;Manual inspection;IA(Information Architecture);OWASP Top 10;AHP
DO - 10.34163/jkits.2017.12.5.015
ER -
Jae-Ho Lee and Sang-Joon Lee. (2017). Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size. Journal of Knowledge Information Technology and Systems, 12(5), 747-763.
Jae-Ho Lee and Sang-Joon Lee. 2017, "Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size", Journal of Knowledge Information Technology and Systems, vol.12, no.5 pp.747-763. Available from: doi:10.34163/jkits.2017.12.5.015
Jae-Ho Lee, Sang-Joon Lee "Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size" Journal of Knowledge Information Technology and Systems 12.5 pp.747-763 (2017) : 747.
Jae-Ho Lee, Sang-Joon Lee. Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size. 2017; 12(5), 747-763. Available from: doi:10.34163/jkits.2017.12.5.015
Jae-Ho Lee and Sang-Joon Lee. "Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size" Journal of Knowledge Information Technology and Systems 12, no.5 (2017) : 747-763.doi: 10.34163/jkits.2017.12.5.015
Jae-Ho Lee; Sang-Joon Lee. Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size. Journal of Knowledge Information Technology and Systems, 12(5), 747-763. doi: 10.34163/jkits.2017.12.5.015
Jae-Ho Lee; Sang-Joon Lee. Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size. Journal of Knowledge Information Technology and Systems. 2017; 12(5) 747-763. doi: 10.34163/jkits.2017.12.5.015
Jae-Ho Lee, Sang-Joon Lee. Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size. 2017; 12(5), 747-763. Available from: doi:10.34163/jkits.2017.12.5.015
Jae-Ho Lee and Sang-Joon Lee. "Improvement of Dynamic Web Vulnerability Inspection Method and Procedure by Website Structuring and Calculating Each Page's Action Size" Journal of Knowledge Information Technology and Systems 12, no.5 (2017) : 747-763.doi: 10.34163/jkits.2017.12.5.015