Palestra: Detecting Vulnerabilities in Web Services: Can Developers Rely on Existing Tools?
Prof. Dr. Nuno Antunes do Department of Informatics Engineering do Centre for Informatics and Systems (CISUC) da Universidade de Coimbra - Coimbra - Portugal, na Série de Seminários 2011 da Pós-Graduação, dia 19/08/2011, às 14:00 h, Sala CC16 (Sala 316) - IC 3.
| What | Palestra |
|---|---|
| When |
19/08/2011 from 14:00 to 15:00 |
| Where | Sala CC16 (Sala 316) - IC 3 |
| Add event to calendar |
|
Although web services are business-critical components, they are often deployed with software bugs that can be maliciously exploited. The majority of the developers are not specialized on security and the common time-to-market constraints limit an in-depth testing for vulnerabilities. In this context, vulnerability detection tools have a very important role helping the developers to produce less vulnerable code. However, developers usually select a tool to use and rely on its results without knowing its real effectiveness. This presentation introduces the research work in security on web services developed in the University of Coimbra. Two case studies are presented to discuss the effectiveness of vulnerability detection tools for web services. The goal is to provide developers with information on how much they can rely on widely used vulnerability detection tools during the development process. Finally, it is presented the work on improving vulnerability detection tools for web services and open research paths on this area. ================================================================
Organizadora: Profa. Anamaria Gomide (anamaria@ic.unicamp.br) IC -- Unicamp Fone: (019) 3521-5884 ================================================================
