Testing and comparing web vulnerability scanning tools for SQL injection and XSS attacks

被引:73
|
作者
Fonseca, Jose [1 ]
Vieira, Marco [2 ]
Madeira, Henrique [2 ]
机构
[1] CISUC, Polithecn Inst Guarda, P-6300 Guarda, Portugal
[2] Univ Coimbra, CISUC, DEI, P-3030 Coimbra, Portugal
关键词
D O I
10.1109/PRDC.2007.55
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web applications are typically developed with hard time constraints and are often deployed with security vulnerabilities. Automatic web vulnerability scanners can help to locate these vulnerabilities and are popular tools among developers of web applications. Their purpose is to stress the application from the attacker's point of view by issuing a huge amount of interaction within it. Two of the most widely spread and dangerous vulnerabilities in web applications are SQL injection and Cross Site Scripting (XSS), because of the damage they may cause to the victim business. Trusting the results of web vulnerability scanning tools is of utmost importance. Without a clear idea on the coverage and false positive rate of these tools, it is difficult to judge the relevance of the results they provide. Furthermore, it is difficult, if not impossible, to compare key figures of merit of web vulnerability scanners. In this paper we propose a method to evaluate and benchmark automatic web vulnerability scanners using software fault injection techniques. The most common types of software faults are injected in the web application code which is then checked by the scanners. The results are compared by analyzing coverage of vulnerability detection and false positives. Three leading commercial scanning tools are evaluated and the results show that in general the coverage is low and the percentage of false positives is very high.
引用
收藏
页码:365 / +
页数:2
相关论文
共 50 条
  • [21] A Top Web Security Vulnerability SQL Injection attack - Survey
    Abirami, J.
    Devakunchari, R.
    Valliyammai, C.
    2015 SEVENTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC), 2015,
  • [22] Comparing Machine Learning for SQL Injection Detection in Web Systems
    Lopez-Tenorio, Brandom
    Dominguez-Isidro, Saul
    Cortes-Verdin, Maria Karen
    Perez-Arriaga, Juan Carlos
    2023 10TH INTERNATIONAL CONFERENCE ON SOFT COMPUTING & MACHINE INTELLIGENCE, ISCMI, 2023, : 17 - 21
  • [23] A Case Study on Web Application Vulnerability Scanning Tools
    Daud, Nor Izyani
    Abu Bakar, Khairul Azmi
    Hasan, Mohd Shafeq Md
    2014 SCIENCE AND INFORMATION CONFERENCE (SAI), 2014, : 595 - 600
  • [24] Comparing the Effectiveness of Penetration Testing and Static Code Analysis on the Detection of SQL Injection Vulnerabilities in Web Services
    Antunes, Nuno
    Vieira, Marco
    IEEE 15TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING, PROCEEDINGS, 2009, : 301 - 306
  • [25] Improving Web Application Firewalls to Detect Advanced SQL Injection Attacks
    Makiou, Abdelhamid
    Begriche, Youcef
    Serhrouchni, Ahmed
    2014 10TH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY (IAS), 2014, : 35 - 40
  • [26] TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
    Yang, Guan-Yan
    Wang, Farn
    Gu, You-Zong
    Teng, Ya-Wen
    Yeh, Kuo-Hui
    Ho, Ping-Hsueh
    Wen, Wei-Ling
    APPLIED SCIENCES-BASEL, 2024, 14 (18):
  • [27] Designing vulnerability testing tools for web services: approach, components, and tools
    Antunes, Nuno
    Vieira, Marco
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2017, 16 (04) : 435 - 457
  • [28] Designing vulnerability testing tools for web services: approach, components, and tools
    Nuno Antunes
    Marco Vieira
    International Journal of Information Security, 2017, 16 : 435 - 457
  • [29] Automatically Repairing Web Application Firewalls Based on Successful SQL Injection Attacks
    Appelt, Dennis
    Panichella, Annibale
    Briand, Lionel
    2017 IEEE 28TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE), 2017, : 339 - 350
  • [30] Joza: Hybrid Taint Inference for Defeating Web Application SQL Injection Attacks
    Naderi-Afooshteh, Abbas
    Anh Nguyen-Tuong
    Bagheri-Marzijarani, Mandana
    Hiser, Jason D.
    Davidson, Jack W.
    2015 45TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, 2015, : 172 - 183