Browse wiki

From Navigators

Jump to: navigation, search
Publication:DSN21-fa
Abstract The vast majority of online services we us The vast majority of online services we use nowadays provide their web application to the users. The correctness of the source code of these applications is crucial to prevent attackers from exploiting its vulnerabilities, leading to severe consequences like the disclosure of sensitive information or the degradation of the availability of the application. Currently, multiple existent solutions analyse and detect vulnerabilities in the source code. Attackers, however, do not usually have access to the source code and must work with the information that is made public. Their goals are clear -- exploit vulnerabilities without accessing the code --, and they resort of black-box fuzzing tools to achieve such. In this paper, we propose an ensemble fuzzing approach to check the correctness of the web applications from the point of view of an attacker and, in a posterior phase, analyse the source code to correlate with the collected information. The approach focuses first on the quality of fuzzers’ crawlers and afterwards on fuzzers capabilities of exploiting the results of all crawlers between them, in order to provide better coverage and precision in the detection of web vulnerabilities. Our preliminary results show that the ensemble performs better than fuzzers individually. performs better than fuzzers individually.
Author João Caseirito + , Ibéria Medeiros +
Booktitle In Proceedings of the 51st IEEE/IFIP International Conference on Dependable Systems and Networks (DSN'21)  +
Key DSN21-fa  +
Month jun  +
NumPubDate 2,021.06  +
Project Project:SEAL +
ResearchLine Fault and Intrusion Tolerance in Open Distributed Systems (FIT) +
Title Finding Web Application Vulnerabilities with an Ensemble Fuzzing (fast abstract)  +
Type inproceedings  +
Year 2021  +
Has improper value forThis property is a special property in this wiki. Url  +
Categories Publication  +
Modification dateThis property is a special property in this wiki. 26 September 2021 18:31:32  +
hide properties that link here 
  No properties link to this page.
 

 

Enter the name of the page to start browsing from.
Views
Personal tools
Toolbox
Navigators toolbox