Testing and comparing web vulnerability scanning tools for SQL injection and XSS attacks

被引:73
|
作者
Fonseca, Jose [1 ]
Vieira, Marco [2 ]
Madeira, Henrique [2 ]
机构
[1] CISUC, Polithecn Inst Guarda, P-6300 Guarda, Portugal
[2] Univ Coimbra, CISUC, DEI, P-3030 Coimbra, Portugal
关键词
D O I
10.1109/PRDC.2007.55
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web applications are typically developed with hard time constraints and are often deployed with security vulnerabilities. Automatic web vulnerability scanners can help to locate these vulnerabilities and are popular tools among developers of web applications. Their purpose is to stress the application from the attacker's point of view by issuing a huge amount of interaction within it. Two of the most widely spread and dangerous vulnerabilities in web applications are SQL injection and Cross Site Scripting (XSS), because of the damage they may cause to the victim business. Trusting the results of web vulnerability scanning tools is of utmost importance. Without a clear idea on the coverage and false positive rate of these tools, it is difficult to judge the relevance of the results they provide. Furthermore, it is difficult, if not impossible, to compare key figures of merit of web vulnerability scanners. In this paper we propose a method to evaluate and benchmark automatic web vulnerability scanners using software fault injection techniques. The most common types of software faults are injected in the web application code which is then checked by the scanners. The results are compared by analyzing coverage of vulnerability detection and false positives. Three leading commercial scanning tools are evaluated and the results show that in general the coverage is low and the percentage of false positives is very high.
引用
收藏
页码:365 / +
页数:2
相关论文
共 50 条
  • [41] Vulnerability Assessment of IPv6 Websites to SQL Injection and Other Application Level Attacks
    Cho, Ying-Chiang
    Pan, Jen-Yi
    SCIENTIFIC WORLD JOURNAL, 2013,
  • [42] Protecting Web Applications from SQL Injection Attacks by using Framework and Database Firewall
    Manikanta, Yakkala V. Naga
    Sardana, Anjali
    PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI'12), 2012, : 609 - 613
  • [43] Analysis of Effectiveness of Black-Box Web Application Scanners in Detection of Stored SQL Injection and Stored XSS Vulnerabilities
    Parvez, Muhammad
    Zavarsky, Pavol
    Khoury, Nidal
    2015 10TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2015, : 186 - 191
  • [44] W3BnNr: An Automated tool for information gathering, vulnerability scanning, attacking and reporting for injection attacks on web application
    Muralidharan, M.
    Babu, Keshav Balaji
    Sujatha, G.
    2023 ADVANCED COMPUTING AND COMMUNICATION TECHNOLOGIES FOR HIGH PERFORMANCE APPLICATIONS, ACCTHPA, 2023,
  • [45] Mitigation from SQL Injection Attacks on Web Server using Open Web Application Security Project Framework
    Fadlil, A.
    Riadi, I.
    Mu'min, M. A.
    INTERNATIONAL JOURNAL OF ENGINEERING, 2024, 37 (04): : 635 - 645
  • [46] Fault-based testing for discovering SQL injection vulnerabilities in web applications
    Alsmadi I.
    AlEroud A.
    Saifan A.A.
    International Journal of Information and Computer Security, 2021, 16 (1-2): : 51 - 62
  • [47] DIAVA: A Traffic-Based Framework for Detection of SQL Injection Attacks and Vulnerability Analysis of Leaked Data
    Gu, Haifeng
    Zhang, Jianning
    Liu, Tian
    Hu, Ming
    Zhou, Junlong
    Wei, Tongquan
    Chen, Mingsong
    IEEE TRANSACTIONS ON RELIABILITY, 2020, 69 (01) : 188 - 202
  • [48] Cross-Site Scripting (XSS) and SQL Injection Attacks Multi-classification Using Bidirectional LSTM Recurrent Neural Network
    Farea, Abdulgbar A. R.
    Wang, Chengliang
    Farea, Ebraheem
    Alawi, Abdulfattah Ba
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON PROGRESS IN INFORMATICS AND COMPUTING (PIC), 2021, : 358 - 363
  • [49] Assessing and Comparing Vulnerability Detection Tools for Web Services: Benchmarking Approach and Examples
    Antunes, Nuno
    Vieira, Marco
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2015, 8 (02) : 269 - 283
  • [50] Toward an SDN-Based Web Application Firewall: Defending against SQL Injection Attacks
    Alotaibi, Fahad M.
    Vassilakis, Vassilios G.
    FUTURE INTERNET, 2023, 15 (05)