WEB dynamic security flaw detection method based on JAVA
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANGZHOU ANHENG INFORMATION TECH CO LTD
- Publication Date
- 2014-04-02
Smart Images
Figure 1 Figure 2
Abstract
Description
technical field
[0001] The invention relates to WEB application security testing, in particular to a JAVA-based WEB dynamic security loophole detection method. Background technique
[0002] In WEB application security testing, frequently used detection methods are usually black-box testing and white-box testing. But both black-box testing and white-box testing have different defects.
[0003] Black-box testing can only find out all the errors in the program only when the test method of exhaustive input information is adopted and all possible input information is considered as the test situation. In fact, there are infinitely many test situations, and people not only need to test all legal information inputs, but also test those information inputs that are illegal but possible. From this point of view, it is impossible to complete the test, so we need to conduct targeted security vulnerability testing, guide the implementation of testing by formulating test cases, and ensur...