Reference Hub5
Agile Development of Secure Web-Based Applications

Agile Development of Secure Web-Based Applications

A. F. Tappenden, T. Huynh, J. Miller, A. Geras, M. Smith
Copyright: © 2006 |Volume: 1 |Issue: 2 |Pages: 24
ISSN: 1554-1045|EISSN: 1554-1053|ISSN: 1554-1045|EISBN13: 9781615203574|EISSN: 1554-1053|DOI: 10.4018/jitwe.2006040101
Cite Article Cite Article

MLA

Tappenden, A. F., et al. "Agile Development of Secure Web-Based Applications." IJITWE vol.1, no.2 2006: pp.1-24. http://doi.org/10.4018/jitwe.2006040101

APA

Tappenden, A. F., Huynh, T., Miller, J., Geras, A., & Smith, M. (2006). Agile Development of Secure Web-Based Applications. International Journal of Information Technology and Web Engineering (IJITWE), 1(2), 1-24. http://doi.org/10.4018/jitwe.2006040101

Chicago

Tappenden, A. F., et al. "Agile Development of Secure Web-Based Applications," International Journal of Information Technology and Web Engineering (IJITWE) 1, no.2: 1-24. http://doi.org/10.4018/jitwe.2006040101

Export Reference

Mendeley
Favorite Full-Issue Download

Abstract

This article outlines a four-point strategy for the development of secure Web-based applications within an agile development framework and introduces strategies to mitigate security risks commonly present in Web-based applications. The proposed strategy includes the representation of security requirements as test cases supported by the open source tool FIT, the deployment of a highly testable architecture allowing for security testing of the application at all levels, the outlining of an extensive security testing strategy supported by the open source unit-testing framework HTTPUnit, and the introduction of the novel technique of security refactoring that transforms insecure working code into a functionally equivalent secure code. Today, many Web-based applications are not secure, and limited literature exists concerning the use of agile methods within this domain. It is the intention of this article to further discussions and research regarding the use of an agile methodology for the development of secure Web-based applications.

Request Access

You do not own this content. Please login to recommend this title to your institution's librarian or purchase it from the IGI Global bookstore.