• DocumentCode
    3749985
  • Title

    Analysis of effectiveness of black-box web application scanners in detection of stored SQL injection and stored XSS vulnerabilities

  • Author

    Muhammad Parvez;Pavol Zavarsky;Nidal Khoury

  • Author_Institution
    Information System Security Management, Concordia University of Edmonton, Edmonton, Alberta, Canada
  • fYear
    2015
  • Firstpage
    186
  • Lastpage
    191
  • Abstract
    Stored SQL injection (SQLI) and Stored Cross Site Scripting (XSS) are the top most critical web application vulnerabilities in present time. Previous researches have shown that black-box scanners have relatively poor performance in detecting these two vulnerabilities. In this paper, we analyze the performance and detection capabilities of latest black-box web application security scanners against stored SQLI and stored XSS. Our analysis shows that the recent scanners are showing improved performance in detection of stored SQLI and stored XSS. We developed our custom test-bed to challenge the scanners´ capabilities to detect stored SQLI and stored XSS. Our analysis revealed that black box scanners still need improvements in detecting stored SQLI and stored XSS vulnerabilities. In addition to the results of performance tests, the paper provides a set of recommendations that could enhance performance of scanners in detecting stored SQLI and stored XSS vulnerabilities.
  • Keywords
    "Databases","Authentication","Testing","Servers","Internet","Java"
  • Publisher
    ieee
  • Conference_Titel
    Internet Technology and Secured Transactions (ICITST), 2015 10th International Conference for
  • Type

    conf

  • DOI
    10.1109/ICITST.2015.7412085
  • Filename
    7412085