摘要
针对传统的Web service安全性测试方法存在的低效性和盲目性,提出了一种基于Web service日志挖掘的安全关联规则挖掘算法,并阐述了算法的应用环境。通过该算法挖掘出正常行为的关联规则,采用错误注入的方式对Web service注入预先设计的构造算子,并把执行后的日志与关联规则进行比较,进而发现Web service存在的安全性问题。实验结果表明,该算法较大地提高了日志挖掘的效率及覆盖率,同时应用该算法能较好地检测出Web service的安全性问题,进一步表明提出的算法是可行有效的。
To solve the inefficiency and blindness of the traditional method of security testing,this paper proposed a new log mining algorithm based on Web service and described the applied environment of the algorithm.The association rules were mined from the normal behavior by this algorithm.It injected the mutation operator into the Web service by fault injection method,compared the execution log with the association rules,and then found out the security problems existed in Web service.The results show that the algorithm can greatly improve the efficiency and coverage rate of log mining and detect the problems of Web service better.The proposed algorithm is feasible and effective.
出处
《计算机应用研究》
CSCD
北大核心
2012年第5期1802-1805,共4页
Application Research of Computers
基金
国家自然科学基金资助项目(61063013)
国家教育部博士点专项基金资助项目(20103227120005)