EconPapers    
Economics at your fingertips  
 

The Theory and Implementation of InputValidator: A Semi-Automated Value-Level Bypass Testing Tool

J. Miller, L. Zhang, E. Ofuonye and M. Smith
Additional contact information
J. Miller: University of Alberta, Canada
L. Zhang: University of Alberta, Canada
E. Ofuonye: University of Alberta, Canada
M. Smith: University of Calgary, Canada

International Journal of Information Technology and Web Engineering (IJITWE), 2008, vol. 3, issue 3, 28-45

Abstract: The construction and testing of Web-based systems has become more complex and challenging because of continual innovations in technology. Security is a major concern, particularly for the deployment of mission critical applications. One of the principal vulnerabilities in Webbased systems revolves around insufficient and inappropriate input validation, a deficiency that can be exploited by attacks that bypass client-side checking. This article describes a partially automated mechanism, the tool InputValidator, which seeks to address this issue by sending test data directly to the server to test the robustness and security of the back-end software. The tool allows a user to construct, execute, and evaluate a number of test cases through a formfilling exercise instead of writing bespoke test code.

Date: 2008
References: Add references at CitEc
Citations:

Downloads: (external link)
http://services.igi-global.com/resolvedoi/resolve. ... 018/jitwe.2008070103 (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:igg:jitwe0:v:3:y:2008:i:3:p:28-45

Access Statistics for this article

International Journal of Information Technology and Web Engineering (IJITWE) is currently edited by Ghazi I. Alkhatib

More articles in International Journal of Information Technology and Web Engineering (IJITWE) from IGI Global
Bibliographic data for series maintained by Journal Editor ().

 
Page updated 2025-03-19
Handle: RePEc:igg:jitwe0:v:3:y:2008:i:3:p:28-45