DetLogic: A black-box approach for detecting logic vulnerabilities in web applications

2018 ◽  
Vol 109 ◽  
pp. 89-109 ◽  
Author(s):  
G. Deepa ◽  
P. Santhi Thilagam ◽  
Amit Praseed ◽  
Alwyn R. Pais
2014 ◽  
Vol 989-994 ◽  
pp. 4542-4546 ◽  
Author(s):  
Jie Fan ◽  
Peng Gao ◽  
Cong Cong Shi ◽  
Ni Ge Li

Contrary to high false positives rate of use White-box testing tools for Web application source code security and unable to locate vulnerabilities of use Black-box testing tools for Web application security, propose an effective method for combine White-box and Black-box testing tools of Web applications. This method will put the new technology of “Associated Files Matching Engine” into White-box testing tools, this test result and Black-box test result will be statistical analyzed and combined. Argumentation show, this method reduce the positives rate of White-box test result and be able to locate vulnerabilities where it is in file.


2021 ◽  
Vol 12 (2) ◽  
pp. 139
Author(s):  
Massimiliano Rak ◽  
Umberto Villano ◽  
Marta Catillo ◽  
Luciano Ocone

JURTEKSI ◽  
2020 ◽  
Vol 6 (2) ◽  
pp. 135-144
Author(s):  
Dian Nurdiana

Abstract: The Information Systems Study Program is one of the study programs at the Open University. The duties and responsibilities of the study program are managing academic and non-academic services. Management of incoming and outgoing mail is one of the tasks that must be carried out so that the service process is maximized. But the management is still manually so that problems occur such as difficulty in finding incoming or outgoing mail because it is still stored in folders, can only be accessed by one person because it is still stored on a computer and it is difficult to classify incoming mail. Therefore there must be a web-based incoming and outgoing mail management application. The purpose of this research is to implement a web-based incoming and outgoing mail application in the Information Systems Study Program. The model used for its development uses the waterfall model, while the testing model uses a black box. The results of this study are knowing the usability of implementing incoming and outgoing letters in the Information Systems Study Program.                  Keywords: Black Boxes; Outgoing Letters; Incoming Letters; Waterfalls; Web Applications.  Abstrak: Program Studi Sistem Informasi merupakan salah satu program studi yang ada di Universitas Terbuka. Tugas dan tanggung jawab program studi adalah mengelola layanan akademik maupun non akademik. Pengelolaan surat masuk dan surat keluar merupakan salah satu tugas yang harus dijalankan agar proses layanan menjadi maksimal. Namun pengelolaannya masih secara manual sehingga terjadi permasalahan seperti sulitnya mencari surat yang masuk atau surat yang keluar karena masih di simpan dalam folder-folder, hanya bisa di akses oleh satu orang karena masih disimpan dalam sebuah komputer dan sulit mengklasifikasikan surat yang masuk. Oleh sebab itu harus ada sebuah aplikasi pengelolaan surat masuk dan surat keluar berbasis web. Tujuan dari penelitian ini adalah mengimplementasikan aplikasi surat masuk dan surat keluar berbasis web di Program Studi Sistem Informasi. Model yang digunakan untuk pengembangannya menggunakan model watelfall, sedangkan model pengujiannya menggunakan black box. Hasil dari penelitian ini adalah mengetahui usability dari implementasi surat masuk dan surat keluar di Program Studi Sistem Informasi Kata kunci: Aplikasi Web; Black Box; Surat Keluar; Surat Masuk; Waterfall.


2013 ◽  
Vol 7 (3) ◽  
pp. 519-531 ◽  
Author(s):  
Zhejun Fang ◽  
Yuqing Zhang ◽  
Ying Kong ◽  
Qixu Liu

Author(s):  
Vijay Kasi ◽  
Brett Young

The term Web services has as many definitions as there are people who have worked on it. The different definitions, in general, stress various aspects of Web services. The diverse nature of these definitions confirms the diverse interpretations of Web services (“Evolution of Integration Functionality,” 2001; Freger, 2001; Infravio, 2002; Ogbuji, 2002; Stal, 2002; Wilkes, 2002). The big computer giants such as Microsoft and IBM promote Web services, and the definitions offered by them are as follows. • IBM: “A Web Service is a collection of functions that are packaged as a single entity and published to the network for use by other programs...[They are] self-describing, self-contained, modular applications...” (Glass, 2000). • Microsoft: “Web Services are a very general model for building applications and can be implemented for any operating system that supports communication over the Internet and represent black-box functionality that can be reused without worrying about how the service is implemented...[They use] building blocks for constructing distributed Web applications...” (Kirtland, 2001). • World Wide Web Consortium (W3C): “A software system identified by a URI [uniform resource indicator], whose public interfaces and bindings are defined and described using XML [extensible markup language]. Its definition can be discovered by other software systems. These systems may then interact in a manner prescribed by its definition, using XML based messages conveyed by internet protocols” (W3C, 2002). This article attempts to clarify these generic definitions into language that is tangible and meaningful to the reader. To do so, background is given on the systems, applications, and architecture that led to the need and development of Web services.


Sign in / Sign up

Export Citation Format

Share Document