Artigo em revista científica
Web applications security and vulnerability analysis financial web applications security audit – a case study
Tiago Vieira (Vieira, T.); Carlos Serrão (Serrão, C.);
Título Revista
International Journal of Innovative Business Strategies
Ano (publicação definitiva)
2016
Língua
Inglês
País
Reino Unido
Mais Informação
Web of Science®

Esta publicação não está indexada na Web of Science®

Scopus

Esta publicação não está indexada na Scopus

Google Scholar

N.º de citações: 6

(Última verificação: 2024-04-26 09:48)

Ver o registo no Google Scholar

Abstract/Resumo
Information security can no longer be neglected in any area. It is a concern to everyone and every organization. This is particularly important in the finance sector, not only because the financial amounts involved but also clients and organization’s private and sensitive information. As a way to test security in infrastructures, networks, deployed web applications and many other assets, organizations have been performing penetration testing which simulates an attacker’s behavior in a controlled environment in order to identify its vulnerabilities. This article focus on the analysis of the results of security audits conducted on several financial web applications from one institution with aid of automatic tools in order to assess their web applications security level. To help in security matters, many organizations build security frameworks for vulnerability assessment, security assessment, threat modeling, penetration testing, risk management and many more. As for penetration testing, organizations such as OWASP provide vulnerability and security information, a testing methodology, risk analysis and penetration testing tools.
Agradecimentos/Acknowledgements
--
Palavras-chave
Security,Web applications,Web security,OWASP
Registos de financiamentos
Referência de financiamento Entidade Financiadora
UID/MULTI/0446/2013 Fundação para a Ciência e a Tecnologia