Automated testing of complex Web 2.0 applications prevents security vulnerabilities

Mar 01, 2013
Automated testing of complex Web 2.0 applications prevents security vulnerabilities
Computer scientists from Saarland University have developed a software system for checking complex web applications autonomously. Credit: bellhäuser - das bilderwerk

So far there are no methods to test complex web 2.0 applications systematically and at low cost for malfunctions and security vulnerabilities. Therefore, computer scientists from Saarland University have developed a software system for checking complex web applications autonomously.

"The police have discovered a new variant of . The offender capitalizes on the complexity of social networks", reported a newspaper a month ago in Southern Germany. Valentin Dallmeier, postdoc at the software engineering chair at Saarland University, is not surprised. He says that the methods that and responsible project leaders rely on to try to find and security holes in have been too ineffective and inefficient. "This is still done manually and therefore causes not only very high costs, but also high levels of risk for companies and the community," Martin Burger explains. He works at the software engineering chair, too. Together the two postdocs want to change this serious deficit. Therefore they have developed the software system "Webmate", which determines automatically why Web 2.0 applications fail.

For the transfer of the technology to a spin-off, they have just received 500,000 Euros from the national support program "EXIST" run by the Federal Ministry of Economics and Technology (BMWi). The program is aimed at improving the entrepreneurial environment at universities and and at increasing the number of technology- and knowledge-based business start-ups.

So called Web 2.0 applications run centrally on an online server. Therefore, in contrast to conventional programs, they are not installed on the user's computer or laptop; instead, the user interacts with them via a web browser. In recent years, thanks to new web development technologies such as Asynchronous JavaScript and XML (AJAX), web applications can be used as smoothly as if they were installed on personal computers. AJAX takes care of organizing the transfer of data packets between the user's computer and server in such a way that the delays incurred by the connection are barely noticeable. Hence, not only private users but also companies and the public sector are adopting web applications more and more frequently. However, news about data theft and malfunctions is also reported on a daily basis.

Dallmeier and Burger want to prevent such worst-case scenarios and other breakdowns. Businesses and their responsible web administrators will only have to type in their Web address. Afterwards the system discovers automatically how the different components of the application are connected to each other and via which menus, buttons, and other control panels the users are interacting with the application. Subsequently, it generates and executes test scenarios. If it discovers, for example, that the application is not compatible with a certain version of a browser, or a control panel no longer exists in a new version of the application, the system informs the developer immediately—likewise if a database is not connected, a server does not respond, or a link is dead. The web developer is able to repeat this test at any time.

Dallmeier, Burger and the three other persons planning to found the spin-off are sure that their technology will succeed. They estimate the market potential in Germany alone to be 120 million Euros annually.

Explore further: An operating system in the cloud

More information: www.st.cs.uni-saarland.de/webmate/

add to favorites email to friend print save as pdf

Related Stories

Google building online Chrome application shop

May 19, 2010

Google on Wednesday gave software developers an early peek at an online Chrome Web Store it is building as an emporium for games and other applications built for use on the Web.

How to Protect Your Web Server from Attacks

Oct 11, 2007

The National Institute of Standards and Technology has released a new publication that provides detailed tips on how to make web servers more resistant to potential attacks. Called “Guidelines on Securing Public Web Servers,” ...

An operating system in the cloud

Oct 09, 2012

Computer users are familiar to different degrees with the operating system that gets their machines up and running, whether that is the Microsoft Windows, Apple Mac, Linux, ChromeOS or other operating system. The OS handles ...

Recommended for you

Mozilla lab wants scientists to step out of analog age

23 hours ago

(Phys.org) —Talk about big ideas. Not satisfied to rest on laurels of having brought forth the open source browser Firefox, Mozilla—defined by some as a global project, by others as one of the key open-source ...

'Watch Dogs' video game a sign of the times

Jun 17, 2013

Across the dizzying, colorful show floor at last week's Electronic Entertainment Expo, there were games on display where players could become all manner of things, like a throat-slashing 18th century pirate, ...

Winners and losers at this week's E3

Jun 15, 2013

Since the first battles over "Pong" machines in local arcades four decades ago, video gamers have loved good competition. And this year's Electronic Entertainment Expo—the industry's largest annual gathering—presented ...

Cube Slam: Google's video game plays up WebRTC, WebGL

Jun 14, 2013

(Phys.org) —Google has a new game called Cube Slam where you get to slam a cube into another player's screen target. If you hit the cube against the other player's screen three times, terrific, the screen ...

User comments : 0

More news stories

Cape Wind gets $200M investment from Danish fund

The Cape Wind offshore wind project has secured a $200 million investment from a Danish pension fund in what the wind farm's president said Tuesday is a milestone for the long-delayed project.

New Zealand emerges as guinea pig for global tech firms

When Google chose New Zealand to unveil secret plans for a balloon-driven wi-fi network last weekend, it cemented the country's reputation as a test bed for global tech companies looking to trial their latest innovations, ...