Show simple item record

dc.contributor.authorTatlı, Emin İslam
dc.contributor.authorUrgun, Bedirhan
dc.identifier.citationTatlı, E. İ. ve Urgun, B. (2017). WIVET-benchmarking coverage qualities of web crawlers. Computer Journal, 60(4), 555-572.
dc.descriptionWOS: 000397192400008en_US
dc.description.abstractWeb application vulnerability scanners (WAVS) include crawler components to extract all accessible links of tested web pages in order to identify attack entry points and parameters. After extracting links, they perform different types of attacks over each extracted link and try to find out existing vulnerabilities in the tested web application for reporting. A WAVS tool that has a low-quality crawler component would generate false-negative results, since failing to discover existing links would inhibit detection of possible vulnerabilities exposed through these links. Therefore, the coverage quality of its crawler plays a very important role in the success of a WAVS tool. In this paper, we propose a novel method for analyzing and comparing coverage qualities of WAVS crawlers. We developed WIVET (Web Input Vector Extractor Teaser) as a benchmarking tool for analyzing crawler components of WAVS. WIVET evaluates WAVS crawlers based on their extraction capability of 56 target links that are generated statically or dynamically by WIVET's 21 test cases. We explain WIVET's architecture, all WIVET test cases and target links with code examples, integration of WIVET into WAVS development environments and WAVS benchmarking results in detail.en_US
dc.description.sponsorshipTUBITAK, The Scientific and Technical Research Council of Turkey [BIDEB 2232, 114C104]en_US
dc.description.sponsorshipTUBITAK, The Scientific and Technical Research Council of Turkey (grant BIDEB 2232, Project No.: 114C104).en_US
dc.publisherOxford University Pressen_US
dc.subjectWeb Securityen_US
dc.subjectWeb Application Vulnerability Scanneren_US
dc.subjectBlack-Box Testingen_US
dc.subjectWeb Crawlingen_US
dc.subjectHidden Weben_US
dc.titleWIVET-benchmarking coverage qualities of web crawlersen_US
dc.relation.journalComputer Journalen_US
dc.departmentİstanbul Medipol Üniversitesi, Mühendislik ve Doğa Bilimleri Fakültesi, Elektrik ve Elektronik Mühendisliği Bölümüen_US
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanıen_US

Files in this item


There are no files associated with this item.

This item appears in the following Collection(s)

Show simple item record