Back to results

University of Malta

Testing a web application for security using static code analysis and dynamic analysis

Abstract

dc:description.abstract

Web application nowadays can perform very complex tasks and are therefore being used extensively to carry out many important tasks, processing millions of Euros in online transactions. Due to the fact that web applications are hosted on servers, which can be accessed by anyone, everywhere, this makes them continuously susceptible to attacks by malicious users. This is combined with the power of modem search engines, which can be used even by teenagers to learn how to attack systems. This should not be undermined, since a single vulnerability can completely wipe off a whole system completely. This highlights the importance of appropriately testing web applications for security. Our system is a flexible and extensible tool which uses a combination of static and dynamic analysis to identify security vulnerabilities. The framework also supports correlation of results from multiple static analysers. Any static analyser which can output the intra-procedural dataflow of the system being tested and output results in XML format can be plugged into our tool. This XML file is then transformed into a standard XML file accepted by the dynamic analyser implemented in our tool. The dynamic analyser uses the details from the output of the static analyser to generate attack strings specific to those issues. The generated test script is then submitted to the hosted system and the results are output to the user. From the test cases tried, the number of security vulnerabilities identified by the static analyser were reduced. Thus the developers would have less security vulnerabilities to check manually, thus saving them a lot of time especially in large projects. The implemented system provides a decent proof-of-concept, which can be later extended and improved.

Degree

thesis:*
Grantor dc:publisher.institution
University of Malta
Year dc:date.issued
2008

Subjects

dc:subject × 3

Rights

dc:rights
Statement dc:rights
  • info:eu-repo/semantics/restrictedAccess
Language dc:language.iso
en

Identifiers

dc:identifier.*
Repository record dc:identifier.uri
https://www.um.edu.mt/library/oar/handle/123456789/92277
OAI identifier oai:identifier
oai:www.um.edu.mt:123456789/92277

Chain of custody

source
Harvested from
University of Malta
Base URL
www.um.edu.mt/library/oar/oai/request
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
citation

Testing a web application for security using static code analysis and dynamic analysis. University of Malta, 2008. https://www.um.edu.mt/library/oar/handle/123456789/92277