Toward Security Test Automation for Event Driven GUI Web Contents
The web is taking recently a large percentage of software products. The evolving nature of web applications put a serious challenge on testing, if the people consider the dynamic nature of the current web. More precisely, testing both blocked contents and AJAX interfaces, might create new challenges in terms of test coverage and completeness. In this paper, the authors proposed enhancements and extensions of the current test automation activities. In the proposed framework, user interaction with AJAX interfaces is used to collect DOM violation states. A blocked content is accessed through multiple forms' submission with dynamic contents, and in each iteration the vulnerability events databases are modified.