:::

詳目顯示

回上一頁
題名:以弱點掃描結合修補函數提昇Web App安全品質
書刊名:電腦稽核
作者:賴森堂 引用關係
出版日期:2012
卷期:25
頁次:頁156-165
主題關鍵詞:弱點掃描修補函數安全漏洞Web appWASIPVulnerability scanningRepair functionSecurity holesWASIP
原始連結:連回原系統網址new window
相關次數:
  • 被引用次數被引用次數:期刊(1) 博士論文(0) 專書(0) 專書論文(0)
  • 排除自我引用排除自我引用:0
  • 共同引用共同引用:0
  • 點閱點閱:2
提供客戶最新的資訊、最順暢的溝通管道及最完善的服務品質是各行各業提昇競爭力的重要指標,Web應用軟體(Web Applications; Web App)則是達成這些任務的必要資產。資訊安全的問題對於電腦設備及軟體系統的危害愈來愈嚴重,網際網路的入侵攻擊與系統本身的安全漏洞持續衝擊正常運作的軟體系統,使得Web App安全品質受到嚴重的考驗,為了避免外部入侵與軟體本身的安全漏洞造成用戶重大的損失,如何有效改善Web App安全品質,已成為值得深入探究的課題。早期開發的Web App未能有效的融入安全性,使得運作中的Web App充滿許多安全漏洞與缺失,利用弱點掃描可以找出Web App的安全漏洞與缺失,再結合高品質函數進行修補作業,可以有效改善安全問題與缺失。為此,本文以弱點掃描為基礎,結合可再用修補函數,提出一套Web App安全品質改善程序(Web App Security Improvement Procedure; WASIP),用以修補Web App的安全漏洞與缺失,具體提昇運作中Web App安全品質。
Providing customers new information, convenience communication channels, and the best service quality are important indicator to enhance industries competitivity. Web app is a necessary asset to accomplish these missions. However, information security issues of computer facility and software system are more and more serious. Internet intrusion, system security vulnerabilities continuously attack the normal operation software system to cause Web App security face to serious challenge. How to effectively improve Web App security becomes a topic which worth deeply discuss. In the early, security issues did not be respected in Web App development process often cause Web App full of a lot of security holes and defects. Vulnerability scanner can help identify the secure holes and defects of Web app. Then, combining high quality function to repair the vulnerability can effectively increase Web app security. In this paper, based on vulnerability scanning and reusable repair functions, propose a Web App Security Improvement procedure (WASIP). Applied WASIP to repair Web app secure holes and defects can concretely improve Web app operating security.
期刊論文
1.Apvrille, A.、Pourzandi, M.(2005)。Secure Software Development by Example。IEEE Security & Privacy,3(4),10-17。  new window
2.Davis, N.、Humphrey, W.、Redwine, S. T. Jr.、Zibulski, G.、McGraw, G.(2004)。Processes for Producing Secure Software。IEEE Security & Privacy,2(3),18-25。  new window
3.McGraw, G.(2004)。Software Security。IEEE Security and Privacy,2(2),80-83。  new window
4.Cowan, C.(2003)。Software Security for Open-Source Systems。IEEE Security & Privacy,1(1),38-45。  new window
會議論文
1.賴森堂(2007)。安全軟體建制基礎--軟體安全特性架構之研究。2007數位科技與創新管理研討會。華梵大學。  延伸查詢new window
2.賴森堂(2008)。以量測模式提昇Web應用軟體的安全性。第五屆流通與全球運籌論文研討會。臺中技術學院。  延伸查詢new window
3.賴森堂(2008)。Applying Design Quality for Improving Maintainability of Web Application。ISQM 2008 國際品質管理研討會。高雄。  延伸查詢new window
4.賴森堂(2007)。以介面設計為基礎的軟體安全品質量測模式。中華民國品質學會第四十三屆年會暨第十三屆全國品質管理研討會。臺北。  延伸查詢new window
圖書
1.Fairly, Richard(1985)。Software Engineering Concepts。McGraw-Hill, Inc.。  new window
2.Galin, D.(2004)。Software Quality Assurance。Addison-Wesley。  new window
3.Viega, J.、McGraw, G.(2002)。Building Secure Software。Addison-Wesley。  new window
4.Leveson, N. G.(1995)。Safeware: System Safety and Computers。Addison-Wesley。  new window
5.Deutsch, M. S.、Willis, R. R.(1988)。Software Quality Engineering: A Total Technical and Management Approach。New Jersey:Prentice-Hall Inc.。  new window
6.Brandon, Daniel M.(2008)。Software Engineering for Modern Web Applications: Methodologies and Technologies。IGI Global。  new window
7.Gillies, James、Cailliau, Robert(2000)。How the Web was Born: The Story of the World Wide Web。Oxford University Press。  new window
8.Pressman, R. S.(2010)。Software Engineering: A Practitioner's Approach。New York:McGraw-Hill。  new window
9.McGraw, G.(2006)。Software Security-Building Security In。Addison-Wesley。  new window
其他
1.ISO,IEC(1988)。Information Technology--Software Product Quality. Part I: Quality Model(FCD 9126-1.2)。  new window
 
 
 
 
第一頁 上一頁 下一頁 最後一頁 top
:::
無相關博士論文
 
無相關書籍
 
無相關著作
 
無相關點閱
 
QR Code
QRCODE