Testing and comparing web vulnerability scanning tools for SQL injection and XSS attacks

被引:73
|
作者
Fonseca, Jose [1 ]
Vieira, Marco [2 ]
Madeira, Henrique [2 ]
机构
[1] CISUC, Polithecn Inst Guarda, P-6300 Guarda, Portugal
[2] Univ Coimbra, CISUC, DEI, P-3030 Coimbra, Portugal
关键词
D O I
10.1109/PRDC.2007.55
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web applications are typically developed with hard time constraints and are often deployed with security vulnerabilities. Automatic web vulnerability scanners can help to locate these vulnerabilities and are popular tools among developers of web applications. Their purpose is to stress the application from the attacker's point of view by issuing a huge amount of interaction within it. Two of the most widely spread and dangerous vulnerabilities in web applications are SQL injection and Cross Site Scripting (XSS), because of the damage they may cause to the victim business. Trusting the results of web vulnerability scanning tools is of utmost importance. Without a clear idea on the coverage and false positive rate of these tools, it is difficult to judge the relevance of the results they provide. Furthermore, it is difficult, if not impossible, to compare key figures of merit of web vulnerability scanners. In this paper we propose a method to evaluate and benchmark automatic web vulnerability scanners using software fault injection techniques. The most common types of software faults are injected in the web application code which is then checked by the scanners. The results are compared by analyzing coverage of vulnerability detection and false positives. Three leading commercial scanning tools are evaluated and the results show that in general the coverage is low and the percentage of false positives is very high.
引用
收藏
页码:365 / +
页数:2
相关论文
共 50 条
  • [31] Detecting SQL Injection Web Attacks Using Ensemble Learners and Data Sampling
    Zuech, Richard
    Hancock, John
    Khoshgoftaar, Taghi M.
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 27 - 34
  • [32] An Approach to Detect and Prevent SQL Injection Attacks in Database Using Web Service
    IndraniBalasundaram
    Ramaraj, E.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2011, 11 (01): : 197 - 205
  • [33] Protecting Database Centric Web Services against SQL/XPath Injection Attacks
    Laranjeiro, Nuno
    Vieira, Marco
    Madeira, Henrique
    DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2009, 5690 : 271 - 278
  • [34] Implementation of techniques, standards and safety recommendations to prevent XSS and SQL injection attacks in Java']Java EE RESTful applications
    Guaman, Daniel
    Guaman, Franco
    Jaramillo, Danilo
    Correa, Roddy
    NEW ADVANCES IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 1, 2016, 444 : 691 - 706
  • [35] UniEmbed: A Novel Approach to Detect XSS and SQL Injection Attacks Leveraging Multiple Feature Fusion with Machine Learning Techniques
    Bakir, Rezan
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2025,
  • [36] Search-Based SQL Injection Attacks Testing Using Genetic Programming
    Aziz, Benjamin
    Bader, Mohamed
    Hippolyte, Cerana
    GENETIC PROGRAMMING, EUROGP 2016, 2016, 9594 : 183 - 198
  • [37] An algorithm for detecting SQL injection vulnerability using black-box testing
    Aliero, Muhammad Saidu
    Ghani, Imran
    Qureshi, Kashif Naseer
    Rohani, Mohd Fo'ad
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2020, 11 (01) : 249 - 266
  • [38] An algorithm for detecting SQL injection vulnerability using black-box testing
    Muhammad Saidu Aliero
    Imran Ghani
    Kashif Naseer Qureshi
    Mohd Fo’ad Rohani
    Journal of Ambient Intelligence and Humanized Computing, 2020, 11 : 249 - 266
  • [39] A Security Analysis Tool For Web Application Reinforcement Against SQL Injection Attacks (SQLIAs)
    Lashkaripour, Z.
    Bafghi, A. Ghaemi
    2013 10TH INTERNATIONAL ISC CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2013,
  • [40] Impact Analysis of Preventing Cross Site Scripting and SQL Injection Attacks on Web Application
    Pandurang, Rathod Mahesh
    Karia, Deepak C.
    2015 IEEE BOMBAY SECTION SYMPOSIUM (IBSS), 2015,