Evaluation of Web Security Mechanisms Using Vulnerability & Attack Injection

被引:38
|
作者
Fonseca, Jose [1 ,2 ]
Vieira, Marco [2 ]
Madeira, Henrique [2 ]
机构
[1] Inst Polytech Guarda, Res Unit Inland Dev, Guarda, Portugal
[2] Univ Coimbra, Ctr Informat & Syst, P-3000 Coimbra, Portugal
关键词
Security; fault injection; internet applications; review and evaluation; FAULT INJECTION;
D O I
10.1109/TDSC.2013.45
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we propose a methodology and a prototype tool to evaluate web application security mechanisms. The methodology is based on the idea that injecting realistic vulnerabilities in a web application and attacking them automatically can be used to support the assessment of existing security mechanisms and tools in custom setup scenarios. To provide true to life results, the proposed vulnerability and attack injection methodology relies on the study of a large number of vulnerabilities in real web applications. In addition to the generic methodology, the paper describes the implementation of the Vulnerability & Attack Injector Tool (VAIT) that allows the automation of the entire process. We used this tool to run a set of experiments that demonstrate the feasibility and the effectiveness of the proposed methodology. The experiments include the evaluation of coverage and false positives of an intrusion detection system for SQL Injection attacks and the assessment of the effectiveness of two top commercial web application vulnerability scanners. Results show that the injection of vulnerabilities and attacks is indeed an effective way to evaluate security mechanisms and to point out not only their weaknesses but also ways for their improvement.
引用
收藏
页码:440 / 453
页数:14
相关论文
共 50 条
  • [41] Data breaches in healthcare: security mechanisms for attack mitigation
    Zlatolas, Lili Nemec
    Welzer, Tatjana
    Lhotska, Lenka
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (07): : 8639 - 8654
  • [42] Mitigating Security Risks in Firewalls and Web Applications using Vulnerability Assessment and Penetration Testing (VAPT)
    Alquwayzani, Alanoud
    Aldossri, Rawabi
    Frikha, Mounir
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (05) : 1348 - 1364
  • [43] An Efficient Approach Toward Security of Web Application Using SQL Attack Detection and Prevention Technique
    Bharati, Vishal
    Kumar, Arun
    INVENTIVE COMPUTATION AND INFORMATION TECHNOLOGIES, ICICIT 2021, 2022, 336 : 781 - 792
  • [44] ATAVE: A Framework for Automatic Timing Attack Vulnerability Evaluation
    Park, Jungmin
    Corba, Massimiliano
    de la Serna, Antonio E.
    Vigeant, Richard L.
    Tehranipoor, Mark
    Bhunia, Swarup
    2017 IEEE 60TH INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS (MWSCAS), 2017, : 559 - 562
  • [45] Automatic Web Security Unit Testing: XSS Vulnerability Detection
    Mohammadi, Mahmoud
    Chu, Bill
    Lipford, Heather Richter
    Murphy-Hill, Emerson
    2016 IEEE/ACM 11TH INTERNATIONAL WORKSHOP IN AUTOMATION OF SOFTWARE TEST (AST), 2016, : 78 - 84
  • [46] SQL injection attack detection:Profiling of web application parameter using the sequence pairwise alignment
    Park, Jae-Chul
    Noh, Bong-Nam
    INFORMATION SECURITY APPLICATIONS, 2006, 4298 : 74 - +
  • [47] Ontology for attack detection: An intelligent approach to web application security
    Razzaq, Abdul
    Anwar, Zahid
    Ahmad, H. Farooq
    Latif, Khalid
    Munir, Faisal
    COMPUTERS & SECURITY, 2014, 45 : 124 - 146
  • [48] Analysis of Security Mechanisms of Dark Web Markets
    Wang, Yichao
    Arief, Budi
    Hernandez-Castro, Julio
    PROCEEDINGS OF THE 2024 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2024, 2024, : 120 - 127
  • [49] Influence of security mechanisms on web services interoperability
    Kocbek, Simon
    Juric, Matjaz B.
    ELEKTROTEHNISKI VESTNIK-ELECTROCHEMICAL REVIEW, 2007, 74 (03): : 113 - 118
  • [50] Defeating SQL injection attack in authentication security: an experimental study
    Das, Debasish
    Sharma, Utpal
    Bhattacharyya, D. K.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2019, 18 (01) : 1 - 22