Testing and comparing web vulnerability scanning tools for SQL injection and XSS attacks

被引:73
|
作者
Fonseca, Jose [1 ]
Vieira, Marco [2 ]
Madeira, Henrique [2 ]
机构
[1] CISUC, Polithecn Inst Guarda, P-6300 Guarda, Portugal
[2] Univ Coimbra, CISUC, DEI, P-3030 Coimbra, Portugal
关键词
D O I
10.1109/PRDC.2007.55
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web applications are typically developed with hard time constraints and are often deployed with security vulnerabilities. Automatic web vulnerability scanners can help to locate these vulnerabilities and are popular tools among developers of web applications. Their purpose is to stress the application from the attacker's point of view by issuing a huge amount of interaction within it. Two of the most widely spread and dangerous vulnerabilities in web applications are SQL injection and Cross Site Scripting (XSS), because of the damage they may cause to the victim business. Trusting the results of web vulnerability scanning tools is of utmost importance. Without a clear idea on the coverage and false positive rate of these tools, it is difficult to judge the relevance of the results they provide. Furthermore, it is difficult, if not impossible, to compare key figures of merit of web vulnerability scanners. In this paper we propose a method to evaluate and benchmark automatic web vulnerability scanners using software fault injection techniques. The most common types of software faults are injected in the web application code which is then checked by the scanners. The results are compared by analyzing coverage of vulnerability detection and false positives. Three leading commercial scanning tools are evaluated and the results show that in general the coverage is low and the percentage of false positives is very high.
引用
收藏
页码:365 / +
页数:2
相关论文
共 50 条
  • [1] Detection of SQL Injection and XSS Attacks in Three Tier Web Applications
    Sonewar, Piyush A.
    Thosar, Sonali D.
    2016 INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION CONTROL AND AUTOMATION (ICCUBEA), 2016,
  • [2] An Analytical Scanning Technique to Detect and Prevent the Transformed SQL Injection and XSS Attacks
    Qbea'h, Mohammad
    Alrabaee, Saed
    Mouheb, Djedjiga
    ICISSP: PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2020, : 603 - 610
  • [3] SQL-injection vulnerability scanning tool for automatic creation of SQL-injection attacks
    Ali, Abdul Bashah Mat
    Shakhatreh, Ala' Yaseen Ibrahim
    Abdullah, Mohd Syazwan
    Alostad, Jasem
    WORLD CONFERENCE ON INFORMATION TECHNOLOGY (WCIT-2010), 2011, 3
  • [4] SECSIX: security engine for CSRF, SQL injection and XSS attacks
    Nagpal B.
    Chauhan N.
    Singh N.
    International Journal of System Assurance Engineering and Management, 2017, 8 (Suppl 2) : 631 - 644
  • [5] Testing and Comparing Result Scanning Using Web Vulnerability Scanner
    Sagala, Albert
    Manurung, Elni
    ADVANCED SCIENCE LETTERS, 2015, 21 (11) : 3458 - 3462
  • [6] Automated Security Testing Framework for Detecting SQL Injection Vulnerability in Web Application
    Awang, Nor Fatimah
    Abd Manaf, Azizah
    GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: TOMORROW'S CHALLENGES OF CYBER SECURITY, ICGS3 2015, 2015, 534 : 160 - 171
  • [7] String Matching Algorithm Based Filter for Preventing SQL Injection and XSS Attacks
    Yadav, Abhishek Kumar
    Kumar, Arun
    INVENTIVE COMPUTATION AND INFORMATION TECHNOLOGIES, ICICIT 2021, 2022, 336 : 793 - 807
  • [8] Prediction of SQL Injection Attacks in Web Applications
    Arumugam, Chamundeswari
    Dwarakanathan, Varsha Bhargavi
    Gnanamary, S.
    Neyveli, Vishalraj Natarajan
    Ramesh, Rohit Kanakuppaliyalil
    Kandhavel, Yeshwanthraa
    Balakrishnan, Sadhanandhan
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2019, PT IV, 2019, 11622 : 496 - 505
  • [9] Design and Implementation of an Automatic Scanning Tool of SQL Injection Vulnerability Based on Web Crawler
    Lei, Xiaochun
    Qu, Jiashi
    Yao, Gang
    Chen, Junyan
    Shen, Xin
    SECURITY WITH INTELLIGENT COMPUTING AND BIG-DATA SERVICES, 2020, 895 : 481 - 488
  • [10] Automatic Web Security Unit Testing: XSS Vulnerability Detection
    Mohammadi, Mahmoud
    Chu, Bill
    Lipford, Heather Richter
    Murphy-Hill, Emerson
    2016 IEEE/ACM 11TH INTERNATIONAL WORKSHOP IN AUTOMATION OF SOFTWARE TEST (AST), 2016, : 78 - 84