Security maturity model of web applications for cyber attacks

Renato Rojas, Ana Muedas, David Mauricio

Producción científica: Capítulo del libro/informe/acta de congresoContribución a la conferenciarevisión exhaustiva

6 Citas (Scopus)

Resumen

Bearing in mind that the projections made for the area of information security point to an increase in attacks on the health sector, added to the lack or little diffusion of security maturity models that allow organizations to know the status of their website in terms of security and that the existing models lack a post-evaluation monitoring, it is necessary to propose a model of security maturity of web applications against cyber-attacks, oriented to the health sector, which is simple to apply. The proposed model will be based on the International Professional Practice Framework methodology and will include the main vulnerabilities published by the Open Web Application Security Project to propose attacks that identify the weakness of the evaluated web system, so that the client company has the possibility to reinforce its weaknesses. Guides will also be proposed to select strategies to improve critical points from a security perspective. As a result of the validation, it was found that, of the 14 tests applied, 5 were approved, positioning the web at level 3 of maturity, which means that there are validations in the structure of the web; however, they are partial or inefficient.

Idioma originalInglés
Título de la publicación alojadaICCSP 2019 - Proceeding of 2019 the 3rd International Conference on Cryptography, Security and Privacy, with workshop 2019 the 4th International Conference on Multimedia and Image Processing, ICMIP 2019
EditorialAssociation for Computing Machinery
Páginas130-137
Número de páginas8
ISBN (versión digital)9781450366182
DOI
EstadoPublicada - 19 ene. 2019
Publicado de forma externa
Evento3rd International Conference on Cryptography, Security and Privacy, ICCSP 2019 with Workshop 2019 the 4th International Conference on Multimedia and Image Processing, ICMIP 2019 - Kuala Lumpur, Malasia
Duración: 19 ene. 201921 ene. 2019

Serie de la publicación

NombreACM International Conference Proceeding Series

Conferencia

Conferencia3rd International Conference on Cryptography, Security and Privacy, ICCSP 2019 with Workshop 2019 the 4th International Conference on Multimedia and Image Processing, ICMIP 2019
País/TerritorioMalasia
CiudadKuala Lumpur
Período19/01/1921/01/19

Nota bibliográfica

Publisher Copyright:
© 2019 Copyright is held by the owner/author(s).

Huella

Profundice en los temas de investigación de 'Security maturity model of web applications for cyber attacks'. En conjunto forman una huella única.

Citar esto