Vulnerability & Attack Injection for Web Applications

被引:22
作者
Fonseca, Jose [1 ]
Vieiraz, Marco [2 ]
Madeira, Henrique [2 ]
机构
[1] Univ Coimbra, Polytech Inst Guarda, CISUC, P-3000 Coimbra, Portugal
[2] Univ Coimbra, CISUC, P-3000 Coimbra, Portugal
来源
2009 IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS & NETWORKS (DSN 2009) | 2009年
关键词
D O I
10.1109/DSN.2009.5270349
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we propose a methodology to inject realistic attacks in web applications. The methodology is based on the idea that by injecting realistic vulnerabilities in a web application and attacking them automatically we can assess existing security mechanisms. To provide true to life results, this methodology relies on field studies of a large number of vulnerabilities in web applications. The paper also describes a set of tools implementing the proposed methodology. They allow the automation of the entire process, including gathering results and analysis. We used these tools to conduct a set of experiments to demonstrate the feasibility and effectiveness of the proposed methodology. The experiments include the evaluation of coverage and false positives of an Intrusion Detection System for SQL Injection and the assessment of the effectiveness of two Web Application Vulnerability Scanners. Results show that the injection of vulnerabilities and attacks is an effective way to evaluate security mechanisms and tools.
引用
收藏
页码:93 / +
页数:2
相关论文
共 21 条
[1]   FAULT INJECTION AND DEPENDABILITY EVALUATION OF FAULT-TOLERANT SYSTEMS [J].
ARLAT, J ;
COSTES, A ;
CROUZET, Y ;
LAPRIE, JC ;
POWELL, D .
IEEE TRANSACTIONS ON COMPUTERS, 1993, 42 (08) :913-923
[2]  
Buehrer G. T., 2005, INT WORKSH SOFTW ENG
[3]   Xception: A technique for the experimental evaluation of dependability in modern computers [J].
Carreira, J ;
Madeira, H ;
Silva, JG .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1998, 24 (02) :125-136
[4]  
Christey S., 2007, VULNERABILITY TYPE D
[5]  
Christey S., 2007, Unforgivable vulnerabilities
[6]  
Christmansson J., 1996, IEEE FAULT TOL COMP
[7]  
Duraes J.A., 2006, Software Engineering, IEEE Transactions on, V32
[8]  
Fonseca J., 2008, IEEE PAC RIM DEP COM
[9]  
FONSECA J, 2007, IEEE PAC RIM INT S D
[10]  
FONSECA J, 2008, IEEE IFIP INT C DEP