Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Automatic detection of access control vulnerabilities in web applications by URL crawling and forced browsing

Full metadata record
DC Field Value Language
dc.contributor.author도경구-
dc.contributor.authorSong, Hong-
dc.contributor.authorKim, Yukyong-
dc.date.accessioned2025-04-01T08:32:37Z-
dc.date.available2025-04-01T08:32:37Z-
dc.date.issued2012-04-
dc.identifier.urihttps://scholarworks.bwise.kr/erica/handle/2021.sw.erica/123079-
dc.description.abstractAccess control vulnerabilities can be disastrous in Web applications. The vulnerabilities might be introduced when developers set up unsafe policies in design phase or inconsistently implement safe policies. Attackers take advantage of the vulnerabilities to obtain the authority of administrator and the sensitive information of another user. Hence, the early detection of access control vulnerabilities is very important. This paper proposes a dynamic analysis that automatically detects access control vulnerabilities in web applications. Given a web site and authorities, accessible URLs for each authority are collected by crawling the web site, and then a chosen subset of the URLs are tested to check whether or not access control vulnerabilities exist for the given authority. We implemented the idea, experimented it with some selected web applications, and found some real access-control vulnerabilities-
dc.language영어-
dc.language.isoENG-
dc.titleAutomatic detection of access control vulnerabilities in web applications by URL crawling and forced browsing-
dc.typeConference-
dc.citation.titleInformation Science and Technology-
dc.citation.volume3-
dc.citation.number2-
dc.citation.startPage482-
dc.citation.endPage486-
dc.identifier.urlhttps://www.semanticscholar.org/paper/Automatic-Detection-of-Access-Control-in-Web-by-URL-Song-Kim/b489858736343940cf21214cb3298ce80c1ad9a7-
Files in This Item
Go to Link
Appears in
Collections
COLLEGE OF COMPUTING > SCHOOL OF COMPUTER SCIENCE > 2. Conference Papers

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Altmetrics

Total Views & Downloads

BROWSE