• DocumentCode
    2392374
  • Title

    Hidden web crawling for SQL injection detection

  • Author

    Wang, Xin ; Wang, Luhua ; Wei, Gengyu ; Zhang, Dongmei ; Yang, Yixian

  • Author_Institution
    Key Lab. of Network & Inf. Attack & Defence Technol. of MOE, Beijing Univ. of Posts & Telecommun., Beijing, China
  • fYear
    2010
  • fDate
    26-28 Oct. 2010
  • Firstpage
    14
  • Lastpage
    18
  • Abstract
    With the development of web technology, the web application has become an important part of our lives. And because of the widely exposed feature of web application/services, any web security vulnerability will mostly be observed and be exploited by hackers. Many the traditional web security scanners [10, 13, 24] have low pages coverage and can´t detect the SQL injection vulnerabilities exist in hidden web pages automatically. In this paper, we propose a mechanism of SQL injection vulnerability detection based on hidden web[16, 18] crawling and implement a detecting system with the purpose of raising the web page coverage and enhancing the SQL injection vulnerability detecting ability of web scanner. We combine authentication with the crawler model, and find SQL injection vulnerability by simulating web attacking and analyzing the data of response. In addition, we also did two experiments, one is to compare the coverage of our tool with other three tradition scanners [10, 13, 24] by detecting three common public web sites, and the result shows that the system we implemented can retrieve hidden web pages and its page coverage is larger than other three scanners; Another experiment shows that the ability to find SQL injection vulnerability in hidden web pages is enhanced. And the result of experiment 2 verified that our detecting system can find SQL injection vulnerabilities in hidden web pages automatically and have lower false positive.
  • Keywords
    SQL; Web services; Web sites; authorisation; SQL injection vulnerability detection; authentication; hidden Web crawling; public Web sites; web application-services; web attacking; web page coverage; web security scanners; web security vulnerability; Hidden web crawler; SQL Injection; Web Scanner; Web security vulnerability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Broadband Network and Multimedia Technology (IC-BNMT), 2010 3rd IEEE International Conference on
  • Conference_Location
    Beijing
  • Print_ISBN
    978-1-4244-6769-3
  • Type

    conf

  • DOI
    10.1109/ICBNMT.2010.5704860
  • Filename
    5704860