Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
web application system web application systems civil aviation business civil aviation industry civil aviation introduction standard background spiral hemp knife 72.5kv/4000a-40ka live tank real-time fluorescence rt-pcr 10-100 90-120 precise laboratory detection rt-rpa
MH/T 0067-2018 in English

MH/T 0067-2018 in English

VALID

Security testing guide for Web application system of civil aviation

  • Issued on:2018-12-14
  • Implemented on:2019-04-01
  • File Format:PDF
  • Delivery:Via email within 1~3 business days
Price(USD): $220.00
$214.00
Standard No: MH/T 0067-2018
Document status: VALID
Title in English: Security testing guide for Web application system of civil aviation
Title in Chinese: 民航Web应用系统安全检测指南
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 1~3 business days
Issued on: 2018-12-14
Implemented on: 2019-04-01
Professional Classification: MH-Civil Aviation
Related Keywords: web application system
web application systems
civil aviation business
civil aviation industry
civil aviation introduction standard background
Related Topics: safety inspection
Civil Aviation Safety
civil aviation
The role of the detection system
Detection system function
Testing Guide
operating system
mh/t 4049-2018
web embolization system
Southeast Asia System Security


Introduction

Standard Background and Technology Evolution

With the acceleration of digital transformation in the civil aviation industry, Web application systems have become key business carriers. This standard is based on the GB/T 22239 security level 3 requirements and is formulated in accordance with the characteristics of civil aviation business, reflecting the technical evolution path from basic protection to active defense.


Comparison of core detection frameworks

Detection dimensions Traditional methods Requirements of this standard Strengthening points
Identity authentication Single-factor authentication Dual-factor + anti-brute force cracking Clause 5.4.2.1 requires combined identification technology
Access control Coarse-grained role Minimum authority + separation of authority Appendix A.2.3 Clarify the authority restriction mechanism
Audit traceability Basic log records Full operation audit + 6 months retention 5.4.2.3 stipulates 14 types of events that must be reviewed

Key points for the implementation of key clauses

4.1.2 Practice of the controllability principle

When a certain airline company tested the ticket booking system:

  • Personnel control: Sign a confidentiality agreement + two-person operation
  • Tool filing: Use the certified Acunetix scanning tool
  • Process recording: Use JIRA to track the entire process

Analysis of typical detection scenarios

Identity authentication test case: According to the requirements of 5.4.2.1.8, simulate the following test process:

  1. Construct a weak password dictionary to implement brute force testing
  2. Verify the effectiveness of the locking mechanism if verification fails
  3. Check the session timeout reset function

Industry implementation recommendations

Phase-based implementation path

Phase Work content Output
Preparation period System asset sorting + detection tool selection Detection Scope Statement
Implementation period Manual inspection + tool scanning + penetration testing 《Testing Process Record Form》
Improvement Period Vulnerability Repair + Configuration Reinforcement 《Safety Rectification Report》

Note: Key business systems should be fully tested twice per year, and closed-loop management should be formed by referring to Chapter 5.5.

Sample only — not a preview of MH/T 0067-2018
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend