TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications

被引:0
|
作者
Yang, Guan-Yan [1 ]
Wang, Farn [1 ]
Gu, You-Zong [1 ,2 ]
Teng, Ya-Wen [1 ]
Yeh, Kuo-Hui [3 ,4 ]
Ho, Ping-Hsueh [1 ]
Wen, Wei-Ling [1 ]
机构
[1] Natl Taiwan Univ, Dept Elect Engn, Taipei 106319, Taiwan
[2] CyberLink Corp, New Taipei 231023, Taiwan
[3] Natl Yang Ming Chiao Tung Univ, Inst Artificial Intelligence Innovat, Hsinchu 300093, Taiwan
[4] Natl Dong Hwa Univ, Dept Informat Management, Hualien 974301, Taiwan
来源
APPLIED SCIENCES-BASEL | 2024年 / 14卷 / 18期
关键词
software testing; penetration testing; automatic testing; information security; SQL injection; testing priority;
D O I
10.3390/app14188365
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
The rapid proliferation of network applications has led to a significant increase in network attacks. According to the OWASP Top 10 Projects report released in 2021, injection attacks rank among the top three vulnerabilities in software projects. This growing threat landscape has increased the complexity and workload of software testing, necessitating advanced tools to support agile development cycles. This paper introduces a novel test prioritization method for SQL injection vulnerabilities to enhance testing efficiency. By leveraging previous test outcomes, our method adjusts defense strength vectors for subsequent tests, optimizing the testing workflow and tailoring defense mechanisms to specific software needs. This approach aims to improve the effectiveness and efficiency of vulnerability detection and mitigation through a flexible framework that incorporates dynamic adjustments and considers the temporal aspects of vulnerability exposure.
引用
收藏
页数:21
相关论文
共 50 条
  • [21] Detection Model for SQL Injection Attack: An Approach for Preventing a Web Application from the SQL Injection Attack
    Buja, Geogiana
    Bin Abd Jalil, Kamarularifin
    Ali, Fakariah Bt Hj Mohd
    Rahman, Teh Faradilla Abdul
    2014 IEEE SYMPOSIUM ON COMPUTER APPLICATIONS AND INDUSTRIAL ELECTRONICS (ISCAIE), 2014,
  • [22] Web Anomaly Misuse Intrusion Detection Framework for SQL Injection Detection
    Salama, Shaimaa Ezzat
    Marie, Mohamed I.
    El-Fangary, Laila M.
    Helmy, Yehia K.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2012, 3 (03) : 123 - 129
  • [23] Testing and comparing web vulnerability scanning tools for SQL injection and XSS attacks
    Fonseca, Jose
    Vieira, Marco
    Madeira, Henrique
    13TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING, PROCEEDINGS, 2007, : 365 - +
  • [24] Analysis and Classification of SQL Injection Vulnerabilities and Attacks on Web Applications
    Sharma, Chandershekhar
    Jain, S. C.
    2014 INTERNATIONAL CONFERENCE ON ADVANCES IN ENGINEERING AND TECHNOLOGY RESEARCH (ICAETR), 2014,
  • [25] Automated Security Testing Framework for Detecting SQL Injection Vulnerability in Web Application
    Awang, Nor Fatimah
    Abd Manaf, Azizah
    GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: TOMORROW'S CHALLENGES OF CYBER SECURITY, ICGS3 2015, 2015, 534 : 160 - 171
  • [26] Formal Analysis of Vulnerabilities of Web Applications Based on SQL Injection
    De Meo, Federico
    Rocchetto, Marco
    Vigano, Luca
    SECURITY AND TRUST MANAGEMENT, STM 2016, 2016, 9871 : 179 - 195
  • [27] How to Prevent SQL Injection Attack Based on Web Applications
    Zheng Haiyan
    Wu Weituan
    Zhang Ruili
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON INDUSTRIAL TECHNOLOGY AND MANAGEMENT SCIENCE (ITMS 2015), 2015, 34 : 854 - 857
  • [28] A Static Detection Method for SQL Injection Vulnerability Based on Program Transformation
    Yuan, Ye
    Lu, Yuliang
    Zhu, Kailong
    Huang, Hui
    Yu, Lu
    Zhao, Jiazhen
    APPLIED SCIENCES-BASEL, 2023, 13 (21):
  • [29] Comparing Machine Learning for SQL Injection Detection in Web Systems
    Lopez-Tenorio, Brandom
    Dominguez-Isidro, Saul
    Cortes-Verdin, Maria Karen
    Perez-Arriaga, Juan Carlos
    2023 10TH INTERNATIONAL CONFERENCE ON SOFT COMPUTING & MACHINE INTELLIGENCE, ISCMI, 2023, : 17 - 21
  • [30] Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services
    Antunes, Nuno
    Laranjeiro, Nuno
    Vieira, Marco
    Madeira, Henrique
    2009 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, 2009, : 260 - 267