WIVET-benchmarking coverage qualities of web crawlers

dc.authorid0000-0003-4562-8486
dc.contributor.authorTatlı, Emin İslam
dc.contributor.authorUrgun, Bedirhan
dc.date.accessioned10.07.201910:49:13
dc.date.accessioned2019-07-10T19:51:33Z
dc.date.available10.07.201910:49:13
dc.date.available2019-07-10T19:51:33Z
dc.date.issued2017
dc.departmentİstanbul Medipol Üniversitesi, Mühendislik ve Doğa Bilimleri Fakültesi, Elektrik ve Elektronik Mühendisliği Bölümü
dc.descriptionWOS: 000397192400008
dc.description.abstractWeb application vulnerability scanners (WAVS) include crawler components to extract all accessible links of tested web pages in order to identify attack entry points and parameters. After extracting links, they perform different types of attacks over each extracted link and try to find out existing vulnerabilities in the tested web application for reporting. A WAVS tool that has a low-quality crawler component would generate false-negative results, since failing to discover existing links would inhibit detection of possible vulnerabilities exposed through these links. Therefore, the coverage quality of its crawler plays a very important role in the success of a WAVS tool. In this paper, we propose a novel method for analyzing and comparing coverage qualities of WAVS crawlers. We developed WIVET (Web Input Vector Extractor Teaser) as a benchmarking tool for analyzing crawler components of WAVS. WIVET evaluates WAVS crawlers based on their extraction capability of 56 target links that are generated statically or dynamically by WIVET's 21 test cases. We explain WIVET's architecture, all WIVET test cases and target links with code examples, integration of WIVET into WAVS development environments and WAVS benchmarking results in detail.
dc.description.sponsorshipTUBITAK, The Scientific and Technical Research Council of Turkey [BIDEB 2232, 114C104]en_US
dc.description.sponsorshipTUBITAK, The Scientific and Technical Research Council of Turkey (grant BIDEB 2232, Project No.: 114C104).en_US
dc.identifier.citationTatlı, E. İ. ve Urgun, B. (2017). WIVET-benchmarking coverage qualities of web crawlers. Computer Journal, 60(4), 555-572. https://dx.doi.org/10.1093/comjnl/bxw072
dc.identifier.doi10.1093/comjnl/bxw072
dc.identifier.endpage572
dc.identifier.issn0010-4620
dc.identifier.issn1460-2067
dc.identifier.issue4
dc.identifier.scopusqualityQ2
dc.identifier.startpage555
dc.identifier.urihttps://dx.doi.org/10.1093/comjnl/bxw072
dc.identifier.urihttps://hdl.handle.net/20.500.12511/2238
dc.identifier.volume60
dc.identifier.wosqualityQ3
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherOxford University Press
dc.relation.ispartofComputer Journalen_US
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.subjectWeb Security
dc.subjectWeb Application Vulnerability Scanner
dc.subjectBlack-Box Testing
dc.subjectWeb Crawling
dc.subjectHidden Web
dc.titleWIVET-benchmarking coverage qualities of web crawlers
dc.typeArticle

Dosyalar