2002Unpublished venueRequires access

Testing Web Security: Assessing the Security of Web Sites and Applications

Steve Splaine

Open publisher page 12 citations

Abstract

From the Publisher: Protect your company’s Web site from hack attacks with this guide to proven security-testing techniques It’s only a matter of time before an unscrupulous would-be intruder decides to attack your organization’s Web site. If they’re successful, you could lose confidential customer information, intellectual property, or e-commerce revenue. Fortunately, this unique book describes a set of security tests that you can perform to ensure your Web site is hack-resistant. Web testing expert Steven Splaine offers a straightforward, easy-to-follow approach to security testing that can be used to check your Web site’s vulnerabilities. Through examples and dozens of testing checklists, you’ll learn how to develop and document a test plan to test the security of a Web site and conduct a risk analysis to help determine which tests should be given the highest priority. Following a straightforward, accessible approach, this book will take you step-by-step through the process of testing the security of your Web sites and applications. Whether you’re a software tester, system administrator, developer, manager, Web master, or security engineer, you’ll find valuable information on how to use testing as a security measure. In this informative book, Steven Splaine covers: Planning the security testing effort: strategies, teams, and tools How to define the scope of the project Testing network security and system software configurations Checking for security vulnerabilities in Web applications Evaluating how well-prepared an organization is against assailants who use social engineering, dumpster diving, insideaccomplices, or physical methods of attack The unique challenges of testing defenses designed to confuse an intruder Using a risk analysis to focus the testing effort on the areas that present the greatest threats to the organization Author Biography: STEVEN SPLAINE is a chartered software engineer with more than twenty years of experience in project management, software testing, and product development. He is a regular speaker at software testing conferences and lead author of The Web Testing Handbook.

About this research paper

What this paper is about

From the Publisher: Protect your company’s Web site from hack attacks with this guide to proven security-testing techniques It’s only a matter of time before an unscrupulous would-be intruder decides to attack your organization’s Web site. If they’re successful, you could lose confidential customer information, intellectual property, or e-commerce revenue. Fortunately, this unique book describes a set of security tests that you can perform to ensure your Web site is hack-resistant. Web testing expert Steven Splaine offers a straightforward, easy-to-follow approach to security testing that can be used to check your Web site’s vulnerabilities. Through examples and dozens of testing checklists, you’ll learn how to develop and document a test plan to test the security of a Web site and conduct a risk analysis to help determine which tests should be given the highest priority. Following a straightforward, accessible approach, this book will take you step-by-step through the process of testing the security of your Web sites and applications. Whether you’re a software tester, system administrator, developer, manager, Web master, or security engineer, you’ll find valuable information on how to use testing as a security measure. In this informative book, Steven Splaine covers: Planning the security testing effort: strategies, teams, and tools How to define the scope of the project Testing network security and system software configurations Checking for security vulnerabilities in Web applications Evaluating how well-prepared an organization is against assailants who use social engineering, dumpster diving, insideaccomplices, or physical methods of attack The unique challenges of testing defenses designed to confuse an intruder Using a risk analysis to focus the testing effort on the areas that present the greatest threats to the organization Author Biography: STEVEN SPLAINE is a chartered software engineer with more than twenty years of experience in project management, software testing, and product development. He is a regular speaker at software testing conferences and lead author of The Web Testing Handbook.

Why it matters

OpenAlex reports 12 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

From the Publisher: Protect your company’s Web site from hack attacks with this guide to proven security-testing techniques It’s only a matter of time before an unscrupulous would-be intruder decides to attack your organization’s Web site. If they’re successful, you could lose confidential customer information, intellectual property, or e-commerce revenue. Fortunately, this unique book describes a set of security tests that you can perform to ensure your Web site is hack-resistant. Web testing expert Steven Splaine offers a straightforward, easy-to-follow approach to security testing that can be used to check your Web site’s vulnerabilities. Through examples and dozens of testing checklists, you’ll learn how to develop and document a test plan to test the security of a Web site and conduct a risk analysis to help determine which tests should be given the highest priority. Following a straightforward, accessible approach, this book will take you step-by-step through the process of testing the security of your Web sites and applications. Whether you’re a software tester, system administrator, developer, manager, Web master, or security engineer, you’ll find valuable information on how to use testing as a security measure. In this informative book, Steven Splaine covers: Planning the security testing effort: strategies, teams, and tools How to define the scope of the project Testing network security and system software configurations Checking for security vulnerabilities in Web applications Evaluating how well-prepared an organization is against assailants who use social engineering, dumpster diving, insideaccomplices, or physical methods of attack The unique challenges of testing defenses designed to confuse an intruder Using a risk analysis to focus the testing effort on the areas that present the greatest threats to the organization Author Biography: STEVEN SPLAINE is a chartered software engineer with more than twenty years of experience in project management, software testing, and product development. He is a regular speaker at software testing conferences and lead author of The Web Testing Handbook.

Key concepts: Web application security, Security testing, Computer security, Computer science, World Wide Web, Web development, Web application, Web testing

Related papers

Back to paper searchBrowse research topicsOriginal source
Testing Web Security: Assessing the Security of Web Sites and Applications — Research Paper | ScholarLens