首页> 外文会议>IEEE/ACM International Workshop on Automation of Software Test >Automatic Web Security Unit Testing: XSS Vulnerability Detection
【24h】

Automatic Web Security Unit Testing: XSS Vulnerability Detection

机译:自动Web安全单元测试:XSS漏洞检测

获取原文

摘要

Integrating security testing into the workflow of software developers not only can save resources for separate security testing but also reduce the cost of fixing security vulnerabilities by detecting them early in the development cycle. We present an automatic testing approach to detect a common type of Cross Site Scripting (XSS) vulnerability caused by improper encoding of untrusted data. We automatically extract encoding functions used in a web application to sanitize untrusted inputs and then evaluate their effectiveness by automatically generating XSS attack strings. Our evaluations show that this technique can detect 0-day XSS vulnerabilities that cannot be found by static analysis tools. We will also show that our approach can efficiently cover a common type of XSS vulnerability. This approach can be generalized to test for input validation against other types injections such as command line injection.
机译:将安全性测试集成到软件开发人员的工作流程中,不仅可以节省不同的安全测试,还可以通过在开发周期早期检测到它们来降低修复安全漏洞的成本。我们提出了一种自动测试方法来检测因不可思议的数据编码不当而导致的跨站点脚本(XSS)漏洞的常见类型。我们自动提取Web应用程序中使用的编码功能以消毒不受信任的输入,然后通过自动生成XSS攻击字符串来评估其效果。我们的评估表明,该技术可以检测到0日XSS漏洞,静态分析工具无法找到。我们还将显示我们的方法可以有效地涵盖常用类型的XSS漏洞。这种方法可以推广以测试对其他类型的输入验证,例如命令行注入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号