Autre (Rapports)
Black-box SQL Injection Testing
APPELT, Dennis; ALSHAHWAN, Nadia; NGUYEN, Duy Cu et al.
2014
 

Documents


Texte intégral
TR-SnT-2014-1.pdf
Postprint Éditeur (490.35 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Mutation Testing; Security Testing; Test Generation
Résumé :
[en] Web services are increasingly adopted in various domains, from finance and e-government to social media. As they are built on top of the web technologies, they suffer also an unprecedented amount of attacks and exploitations like the Web. Among the attacks, those that target SQL injection vulnerabilities have consistently been top-ranked for the last years. Testing to detect such vulnerabilities before making web services public is crucial. We present in this report an automated testing approach, namely μ4SQLi, and its underpinning set of mutation operators. μ4SQLi can produce effective inputs that lead to executable and harmful SQL statements. Executability is key as otherwise no injection vulnerability can be exploited. Our evaluation demonstrated that the approach outperforms contemporary known attacks in terms of vulnerability detection and the ability to get through an application firewall, which is a popular configuration in real world.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust
Disciplines :
Sciences informatiques
Auteur, co-auteur :
APPELT, Dennis ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
ALSHAHWAN, Nadia ;  University College London > Department of Computer Science
NGUYEN, Duy Cu ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
BRIAND, Lionel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) ; University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Langue du document :
Anglais
Titre :
Black-box SQL Injection Testing
Date de publication/diffusion :
28 janvier 2014
ISBN/EAN :
978-2-87971-121-8
N° de rapport :
TR-SnT-2014-1
Organisme subsidiant :
FNR - Fonds National de la Recherche
Disponible sur ORBilu :
depuis le 20 janvier 2014

Statistiques


Nombre de vues
811 (dont 59 Unilu)
Nombre de téléchargements
870 (dont 24 Unilu)

Bibliographie


Publications similaires



Contacter ORBilu