首页> 外文会议>Annual International Conference on Privacy, Security and Trust >Automated detection of session management vulnerabilities in web applications
【24h】

Automated detection of session management vulnerabilities in web applications

机译:Web应用程序中的会话管理漏洞自动检测

获取原文

摘要

Many web applications employ session management to keep track of visitors' activities across pages and over periods of time. A session is a period of time linked to a visitor, which is initiated when he/she arrives at a web application and it ends when his/her browser is closed or after a certain time of inactivity. Attackers can hijack a user's session by exploiting session management vulnerabilities by means of session fixation and cross-site request forgery attacks. Even though such session management vulnerabilities can be eliminated in the development phase of web applications, the test operator is required to have detailed knowledge on the attacks and to set up a test environment each time he/she attempts to detect vulnerabilities. We propose a technique that automatically detects session management vulnerabilities in web applications by simulating real attacks. Our technique requires the test operator to only enter a few pieces of basic information about the web application, without requiring a test environment to be set up or detailed knowledge on the web application. Our experiments demonstrated that our technique could detect vulnerabilities in five web applications deployed in the real world.
机译:许多Web应用程序采用会话管理,以跟踪页面跨页面和一段时间的游客活动。会话是与访问者相关的一段时间,当他/她到达Web应用程序时启动,并且当他/她的浏览器关闭或在一定的不活动时间后结束。攻击者可以通过通过会话修复和跨站点请求伪造攻击利用会话管理漏洞来劫持用户的会话。尽管在Web应用程序的开发阶段可以消除此类会话管理漏洞,但测试运算符需要对攻击有详细的知识,并每次尝试检测漏洞时设置测试环境。我们提出了一种通过模拟真实攻击自动检测Web应用程序中的会话管理漏洞的技术。我们的技术要求测试运算符只输入有关Web应用程序的一些基本信息,而无需在Web应用程序上设置或详细知识。我们的实验表明,我们的技术可以在现实世界部署的五个Web应用程序中检测漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号