Browse > Article
http://dx.doi.org/10.5392/JKCA.2022.22.02.125

Improvement Mechanism for Automatic Web Vulnerability Diagnosis  

Kim, Tae-Seop (배재대학교대학원 사이버보안학과)
Jo, In-June (배재대학교대학원 사이버보안학과)
Publication Information
Abstract
Due to the development of smartphone technology, as of 2020, 91.9% of people use the Internet[1] to frequently acquire information through websites and mobile apps. As the number of homepages in charge of providing information is increasing every year, the number of applications for web vulnerability diagnosis, which diagnoses the safety of homepages, is also increasing. In the existing web vulnerability check, the number of diagnostic personnel should increase in proportion to the number of homepages that need diagnosis because the diagnosticians manually test the homepages for vulnerabilities. In reality, however, there is a limit to securing a web vulnerability diagnosis manpower, and if the number of diagnosis manpower is increased, a lot of costs are incurred. To solve these problems, an automatic diagnosis tool is used to replace a part of the manual diagnosis. This paper explores a new method to expand the current automatic diagnosis range. In other words, automatic diagnosis possible items were derived by analyzing the impact of web vulnerability diagnosis items. Furthermore, automatic diagnosis identified possible items through comparative analysis of diagnosis results by performing manual and automatic diagnosis on the website in operation. In addition, it is possible to replace manual diagnosis for possible items, but not all vulnerability items, through the improvement of automatic diagnosis tools. This paper will explore some suggestions that can help improve plans to support and implement automatic diagnosis. Through this, it will be possible to contribute to the creation of a safe website operating environment by focusing on the parts that require precise diagnosis.
Keywords
Web Vulnerability; Web Vulnerability Check Items; Automatic Diagnosis; Improvement;
Citations & Related Records
Times Cited By KSCI : 1  (Citation Analysis)
연도 인용수 순위
1 https://www.index.go.kr/potal/main/EachDtlPageDetail.do?idx_cd=1363, 2021.10.13.
2 이재호, "웹 페이지 수행기능분석과 점검 우선순위를 활용한 모델기반 웹 취약점 점검," 예술인문사회 융합멀티미디어 논문지, 제9권, 제3호, pp.727-736, 2019.
3 https://owasp.org/Top10/, 2021.
4 https://www.sans.org/top25-software-errors/, 2021.10.14.
5 한국인터넷진흥원, (전자정부 SW 개발.운영자를 위한) 소프트웨어 개발보안 가이드, 2019.11.
6 행정안전부, 웹취약점 점검 항목, 2020.09.
7 최은정, 정휘찬, 김승엽, "크로스 사이트 스크립팅(XSS) 취약점에 대한 공격과 방어," 디지털융복합연구, 제13권, 제2호, pp.177-183, 2015.   DOI
8 김광현, "웹 취약점 분석을 위한 프락시 시스템의 설계 및 구현," 한국전자통신학회 논문지, 제9권, 제9호, pp.1011-1018, 2014.
9 장희선, "Web Vulnerability Scanner를 이용한 취약성 분석," 융합보안논문지, 제12권, 제4호, pp.71-76, 2012.
10 이택진, 손수엘, "오픈 소스 웹 취약점 스캐너의 성능분석," 정보과학회지, 제36권, 제3호, pp.42-49, 2018.03.
11 한국인터넷진흥원, 주요정보통신기반시설 기술적 취약점 분석 평가 상세 가이드, 2021.03.
12 과학기술정보통신부, 2020년 인터넷 이용 실태조사발표, 2021.03.