首页> 外文期刊>Brazilian Computer Society. Journal >An automated black box approach for web vulnerability identification and attack scenario generation
【24h】

An automated black box approach for web vulnerability identification and attack scenario generation

机译:用于网络漏洞识别和攻击场景生成的自动黑匣子方法

获取原文
           

摘要

Web applications have become increasingly vulnerable and exposed to malicious attacks that could affect essential properties of information systems such as confidentiality, integrity, or availability. To cope with these threats, it is necessary to develop efficient security protection mechanisms and assessment techniques (firewall, intrusion detection system, Web scanner, etc.). This paper presents a new methodology, based on Web page clustering techniques, that is aimed at identifying the vulnerabilities of a Web application following a black box analysis of the target application. Each identified vulnerability is actually exploited to ensure that it does not correspond to a false positive. The proposed approach can also highlight different potential attack scenarios including the exploitation of several successive vulnerabilities, taking into account explicitly the dependencies between these vulnerabilities. We have focused in particular on code injection vulnerabilities, such as SQL injections. The proposed methodology led to the development of a new Web vulnerability scanner that has been validated experimentally on several examples of vulnerable applications.
机译:Web应用程序变得越来越脆弱,并容易受到恶意攻击,这些恶意攻击可能会影响信息系统的基本属性,例如机密性,完整性或可用性。为了应对这些威胁,有必要开发有效的安全保护机制和评估技术(防火墙,入侵检测系统,Web扫描仪等)。本文提出了一种基于Web页群集技术的新方法,该方法旨在在对目标应用程序进行黑盒分析之后识别Web应用程序的漏洞。实际上,每个发现的漏洞都被利用以确保它不与误报相对应。所提出的方法还可以突出显示不同的潜在攻击情形,包括对多个连续漏洞的利用,并明确考虑这些漏洞之间的依赖性。我们特别关注代码注入漏洞,例如SQL注入。所提出的方法论导致了新Web漏洞扫描程序的开发,该漏洞扫描程序已在一些易受攻击的应用程序示例中进行了实验验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号