DocumentCode
3308525
Title
Research on strong-association rule based web application vulnerability detection
Author
Tian He ; Xu Jing ; Lian Kunmei ; Zhang Ying
Author_Institution
Inst. of machine Intell., Nankai Univ., Tianjin, China
fYear
2009
fDate
8-11 Aug. 2009
Firstpage
237
Lastpage
241
Abstract
With the increase of the web applications in information society, Web application software security become more and more important. Recent investigations show that web application vulnerabilities have become the largest security threat. Websense security report shows that in the first half of year 2008 above 75% of the most popular Web site have utilized by the hackers to run malicious code. Detecting and solving vulnerability is the effective way to enhance Web security. In this paper we focus on the regression test in web vulnerability detection, and present a strong-association rule based algorithm to make the detection more efficient. In the first step we traverse the whole Web site to get the Web page collection. And then, in the regression test, we make the association between the pages and expand the pages to a collection set. The set will used in the following iterate traverse. And we define the relational grade to describe the association. Finally, we do the experiment on our target Web site which contains the known vulnerabilities such as XSS and SQL injection, and the result shows that the algorithm can detect almost all the pages that may contains vulnerabilities in the target Web site.
Keywords
Internet; data mining; security of data; SQL injection; Web application vulnerability detection; Web page collection; Web security; Web site; software security; strong-association rule based algorithm; Application software; Association rules; Computer hacking; Data security; Helium; Information security; Intrusion detection; Protection; Testing; Web pages; Strong association Rule; Web security testing; Web vulnerability;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Science and Information Technology, 2009. ICCSIT 2009. 2nd IEEE International Conference on
Conference_Location
Beijing
Print_ISBN
978-1-4244-4519-6
Electronic_ISBN
978-1-4244-4520-2
Type
conf
DOI
10.1109/ICCSIT.2009.5234394
Filename
5234394
Link To Document