Repository logo
 
Publication

AUTOMATED, SCHEDULED AND CI /CD WEB INJECTION

datacite.subject.fosEngenharia e Tecnologia::Engenharia Eletrotécnica, Eletrónica e Informáticapt_PT
dc.contributor.advisorGomes, Ricardo Jorge Pereira
dc.contributor.authorZhygulskyy, Mykyta
dc.date.accessioned2021-05-17T13:06:05Z
dc.date.available2021-05-17T13:06:05Z
dc.date.issued2021-01-20
dc.description.abstractThis report is made within the Curricular Unit (UC) Project, in the 2nd year of the Master in Cyber-security and Forensic Informatics (MCIF) provided by the Polytechnic Institute of Leiria (IPL). The purpose of this project is to study SQL Injection vulnerabilities in web applications. According to OWASP (Open Web Application Security Project) [20][19], this is one of the more prevalent attacks on web applications. As part of this work a web application was implemented, which can from a URL address, go through all the endpoints of the target application and test for SQL Injection vulnerabilities. The application also makes allows for scheduling of the tests and it is integrable with Continuous Integration / Continuous Delivery (CI/CD) environments. According to the literature on the subject, there are several algorithms that can be employed to test for existing SQL Injection vulnerabilities in a web application. In this document, we analyze them both from a theoretical and an implementation point of view. In order to better understand the subject, and produce a useful tool in this space. With the development of this project, we concluded that it is possible to integrate SQL vulnerability tests, with CI/CD pipeline and automate the development process of an application, with the execution of SQL injection tests in an automated way.pt_PT
dc.identifier.tid202725685pt_PT
dc.identifier.urihttp://hdl.handle.net/10400.8/5786
dc.language.isoengpt_PT
dc.subjectSegurança informáticapt_PT
dc.subjectPirataria informáticapt_PT
dc.subjectSistema de deteção de intrusão/OWASP (Open web Application Security Project)pt_PT
dc.subjectCI (Continuos Integration)pt_PT
dc.subjectCD (Continuos Delivery)pt_PT
dc.subjectAnálise forense digitapt_PT
dc.titleAUTOMATED, SCHEDULED AND CI /CD WEB INJECTIONpt_PT
dc.typemaster thesis
dspace.entity.typePublication
rcaap.rightsopenAccesspt_PT
rcaap.typemasterThesispt_PT
thesis.degree.nameMestrado em Cibersegurança e Informática Forensept_PT

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Relatorio_vCORRIGIDA_MykytaZhygulskyy_com_correções_formais.pdf
Size:
2.26 MB
Format:
Adobe Portable Document Format
Description: