发明名称 情報処理装置及び情報処理方法及びプログラム
摘要 PROBLEM TO BE SOLVED: To certainly perform a vulnerability inspection to an alteration attack for an important parameter. SOLUTION: A Web page type specification part 122 specifies a type of a test object Web page by referring to information in a Web page feature information DB 121, etc., and a Web page importance determination part 125 specifies a transaction flow to be attained by a test object Web page group by referring to information in a transaction flow pattern DB 124. In the transaction flow pattern DB 124, an important page is defined for every transaction flow, and the Web page importance determination part 125 specifies an important page in the specified transaction flow. In a parameter attribute DB 126, an important parameter is defined, and an important parameter specification part 127 specifies the important parameter in the important page by referring to information in the parameter attribute DB 126. An evaluation data generation part 112 alters the important parameter in the important page to perform a pseudo alteration attack to a Web application 131. COPYRIGHT: (C)2012,JPO&INPIT
申请公布号 JP5618861(B2) 申请公布日期 2014.11.05
申请号 JP20110036664 申请日期 2011.02.23
申请人 发明人
分类号 G06F21/57;G06F21/12 主分类号 G06F21/57
代理机构 代理人
主权项
地址