Please use this identifier to cite or link to this item: https://hdl.handle.net/10316/99206
DC FieldValueLanguage
dc.contributor.advisorVieira, Marco-
dc.contributor.advisorAntunes, Nuno-
dc.contributor.authorVentura, Rafael Simões-
dc.date.accessioned2022-03-08T15:10:26Z-
dc.date.available2022-03-08T15:10:26Z-
dc.date.issued2014-09-
dc.identifier.urihttps://hdl.handle.net/10316/99206-
dc.descriptionDissertação de Mestrado em Engenharia Informática apresentada à Faculdade de Ciências e Tecnologia da Universidade de Coimbra.pt
dc.description.abstractA Service-based infrastructure is a composition of software pieces that provides functionalities that supports organizational large operations. Although they can be composed by any kind of services, web services are often the preferred technology used, due to their characteristics. This kind of infrastructures can be frequently found in online stores, educational and banking systems, making the web services used businesscritical components. However, studies show that many of these services are deployed disregarding security concerns, which results in a huge amount of vulnerable web services in production. The cost of manual code inspection and lack of security expertise of programmers brought the need to use automatic vulnerability scanning tools, yet studies and reports show that the effectiveness of these scanners is insufficient. In fact, experiments from previous work show that existing scanners present a low detection rate and a high number of false positives. To address this problem we need new and improved tools. This works presents a new integrated tool implemented in a modular fashion where the components of vulnerability scanning techniques can be easily integrated without the need of implement new tools for each new technique. With this tool it is possible not only to implement the known techniques but it also enables the evolvement of the same. Among with this tool were built the necessary modules to complete three different techniques. A benchmark was applied to the tool and the results show viability of the modular approach of the integrated tool.pt
dc.language.isoengpt
dc.rightsopenAccesspt
dc.subjectAutomated Toolspt
dc.subjectBlack-box Testingpt
dc.subjectExtensible Toolspt
dc.subjectGray-box Testingpt
dc.subjectModular Developmentpt
dc.subjectSecuritypt
dc.subjectService Oriented Architecturept
dc.subjectSoftware Testingpt
dc.subjectSoftware Vulnerabilitiespt
dc.subjectVulnerability Detectionpt
dc.subjectWeb Servicespt
dc.titleAn Integrated Tool to Detect Vulnerabilities in Service-Based Infrastructurespt
dc.typemasterThesispt
degois.publication.locationCoimbrapt
dc.date.embargo2014-09-01*
thesis.degree.grantor00500::Universidade de Coimbrapt
thesis.degree.nameMestrado em Engenharia Informáticapt
uc.rechabilitacaoestrangeiranopt
uc.date.periodoEmbargo0pt
item.cerifentitytypePublications-
item.languageiso639-1en-
item.fulltextCom Texto completo-
item.grantfulltextopen-
item.openairecristypehttp://purl.org/coar/resource_type/c_18cf-
item.openairetypemasterThesis-
crisitem.advisor.researchunitCISUC - Centre for Informatics and Systems of the University of Coimbra-
crisitem.advisor.parentresearchunitFaculty of Sciences and Technology-
crisitem.advisor.orcid0000-0001-5103-8541-
crisitem.advisor.orcid0000-0002-3067-2145-
Appears in Collections:FCTUC Eng.Informática - Teses de Mestrado
Files in This Item:
File Description SizeFormat
2014-ventura-MSc-final.pdf1.75 MBAdobe PDFView/Open
Show simple item record

Page view(s)

52
checked on May 14, 2024

Download(s)

24
checked on May 14, 2024

Google ScholarTM

Check


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.