首页> 外文会议>2011 IEEE International Conference on Services Computing >Enhancing Penetration Testing with Attack Signatures and Interface Monitoring for the Detection of Injection Vulnerabilities in Web Services
【24h】

Enhancing Penetration Testing with Attack Signatures and Interface Monitoring for the Detection of Injection Vulnerabilities in Web Services

机译:使用攻击签名和接口监视来增强渗透测试,以检测Web Services中的注入漏洞

获取原文

摘要

Web services are often deployed with critical software bugs that may be maliciously exploited. Developers often trust on penetration testing tools to detect those vulnerabilities but the effectiveness of such technique is limited by the lack of information on the internal state of the tested services. This paper proposes a new approach for the detection of injection vulnerabilities in web services. The approach uses attack signatures and interface monitoring to increase the visibility of the penetration testing process, yet without needing to access web service's internals (as these are frequently not available). To demonstrate the feasibility of the approach we implemented a prototype tool to detect SQL Injection vulnerabilities in SOAP. An experimental evaluation comparing this prototype with three commercial penetration testers was conducted. Results show that our prototype is able to achieve much higher detection coverage than those testers while avoiding false positives, indicating that the proposed approach can be used in real development scenarios.
机译:Web服务通常部署有可能被恶意利用的关键软件错误。开发人员通常信任渗透测试工具来检测那些漏洞,但是由于缺乏有关被测试服务内部状态的信息,这种技术的有效性受到了限制。本文提出了一种新的方法来检测Web服务中的注入漏洞。该方法使用攻击签名和界面监视来提高渗透测试过程的可见性,而无需访问Web服务的内部(因为这些内部常常不可用)。为了证明该方法的可行性,我们实现了一个原型工具来检测SOAP中的SQL注入漏洞。进行了该原型与三台商用渗透测试仪的比较实验评估。结果表明,我们的原型能够比那些测试人员实现更高的检测范围,同时避免了误报,表明所提出的方法可以在实际的开发场景中使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号