DocumentCode :
2777279
Title :
An Analysis of Black-Box Web Application Security Scanners against Stored SQL Injection
Author :
Khoury, Nidal ; Zavarsky, Pavol ; Lindskog, Dale ; Ruhl, Ron
Author_Institution :
Concordia Univ. Coll. of Alberta, Edmonton, AB, Canada
fYear :
2011
fDate :
9-11 Oct. 2011
Firstpage :
1095
Lastpage :
1101
Abstract :
Web application security scanners are a compilation of various automated tools put together and used to detect security vulnerabilities in web applications. Recent research has shown that detecting stored SQL injection, one of the most critical web application vulnerabilities, is a major challenge for black-box scanners. In this paper, we evaluate three state of art black-box scanners that support detecting stored SQL injection vulnerabilities. We developed our custom test bed that challenges the scanners capability regarding stored SQL injections. The results show that existing vulnerabilities are not detected even when these automated scanners are taught to exploit the vulnerability. The weaknesses of black-box scanners identified reside in many areas: crawling, input values and attack code selection, user login, analysis of server replies, miss-categorization of findings, and the automated process functionality. Because of the poor detection rate, we discuss the different phases of black-box scanners´ scanning cycle and propose a set of recommendations that could enhance the detection rate of stored SQL injection vulnerabilities.
Keywords :
Internet; SQL; security of data; black-box Web application security scanners; security vulnerabilities; stored SQL injection; Databases; Electronic mail; Registers; Security; Syntactics; Web servers; black-box scanners; stored SQL injection; vulnerabilities;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Privacy, Security, Risk and Trust (PASSAT) and 2011 IEEE Third Inernational Conference on Social Computing (SocialCom), 2011 IEEE Third International Conference on
Conference_Location :
Boston, MA
Print_ISBN :
978-1-4577-1931-8
Type :
conf
DOI :
10.1109/PASSAT/SocialCom.2011.199
Filename :
6113264
Link To Document :
بازگشت