• DocumentCode
    2032180
  • Title

    An automated vulnerability scanner for injection attack based on injection point

  • Author

    Chen, Jan-Min ; Wu, Chia-Lun

  • Author_Institution
    Dept. of Inf. Manage., Yu Da Univ., Miaoli, Taiwan
  • fYear
    2010
  • fDate
    16-18 Dec. 2010
  • Firstpage
    113
  • Lastpage
    118
  • Abstract
    As the popularity of the web increases and web applications become tools of everyday use, the role of web security has been gaining importance as well. The last years have shown a significant increase in the number of web-based attacks. Too many nouns web application security vulnerabilities result from generic input validation problems. Examples of such vulnerabilities are SQL injection and Cross-Site Scripting (XSS). Although the majority of web vulnerabilities are easy to understand and to avoid, many web developers are, unfortunately, not security-aware. As a result, there exist many web sites on the Internet that are vulnerable. This paper implemented an automated vulnerability scanner that for the injection attacks. To this end, we implemented a system that automated scanned the injection attack vulnerabilities. Our system was automatically analyses web sites with the aim of finding exploitable SQL injection and XSS vulnerabilities. It was able to find many potentially vulnerable web sites. We picked 7 identified web sites with vulnerabilities from National Vulnerability Database [13] to verify our system.
  • Keywords
    Internet; security of data; SQL injection; Web security; Web-based attacks; XSS vulnerabilities; automated vulnerability scanner; cross-site scripting; injection attack; injection point; national vulnerability database; Algorithm design and analysis; Crawlers; Databases; Security; Servers; Testing; Web sites; Black-Box Testing; Complete Crawling; SQL-Injection; Security Scanner; Web Application Testing; XSS;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Symposium (ICS), 2010 International
  • Conference_Location
    Tainan
  • Print_ISBN
    978-1-4244-7639-8
  • Type

    conf

  • DOI
    10.1109/COMPSYM.2010.5685537
  • Filename
    5685537