• DocumentCode
    47758
  • Title

    Evaluation of Web Security Mechanisms Using Vulnerability & Attack Injection

  • Author

    Fonseca, J. ; Vieira, Marco ; Madeira, Henrique

  • Author_Institution
    Inst. Polytech. of Guarda, Univ. of Coimbra, Coimbra, Portugal
  • Volume
    11
  • Issue
    5
  • fYear
    2014
  • fDate
    Sept.-Oct. 2014
  • Firstpage
    440
  • Lastpage
    453
  • Abstract
    In this paper we propose a methodology and a prototype tool to evaluate web application security mechanisms. The methodology is based on the idea that injecting realistic vulnerabilities in a web application and attacking them automatically can be used to support the assessment of existing security mechanisms and tools in custom setup scenarios. To provide true to life results, the proposed vulnerability and attack injection methodology relies on the study of a large number of vulnerabilities in real web applications. In addition to the generic methodology, the paper describes the implementation of the Vulnerability & Attack Injector Tool (VAIT) that allows the automation of the entire process. We used this tool to run a set of experiments that demonstrate the feasibility and the effectiveness of the proposed methodology. The experiments include the evaluation of coverage and false positives of an intrusion detection system for SQL Injection attacks and the assessment of the effectiveness of two top commercial web application vulnerability scanners. Results show that the injection of vulnerabilities and attacks is indeed an effective way to evaluate security mechanisms and to point out not only their weaknesses but also ways for their improvement.
  • Keywords
    Internet; SQL; fault diagnosis; security of data; software fault tolerance; SQL Injection attacks; VAIT; Web application security mechanism evaluation; attack injection methodology; fault injection; intrusion detection system; vulnerability injection methodology; vulnerability-&-attack injector tool; Databases; Educational institutions; Input variables; Probes; Security; Software; TV; Security; fault injection; internet applications; review and evaluation;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2013.45
  • Filename
    6629992