BlackBox Web Vulnerability Detection with Model Inference assisted Evolutionary Fuzzing - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

BlackBox Web Vulnerability Detection with Model Inference assisted Evolutionary Fuzzing

Résumé

Fuzzing (aka Fuzz-Testing) consists in testing a system by sending boundary values and observing if a property is violated. Traditional undirected fuzzing techniques lack knowledge of the behavior of the tested system. This limits their ability to generate inputs, and to achieve high coverage. We propose a combination of model inference and evolutionary fuzzing. The former reverse-engineers an application behavior, and the latter evolves malicious inputs for detecting vulnerabilities. We specifically targets Cross Site Scripting (XSS), a particular case of command injection in web applications.
Fichier non déposé

Dates et versions

hal-00853724 , version 1 (23-08-2013)

Identifiants

  • HAL Id : hal-00853724 , version 1

Citer

Fabien Duchene. BlackBox Web Vulnerability Detection with Model Inference assisted Evolutionary Fuzzing. SysSec 2013 - 2nd Workshop on System Security research, Jul 2013, Bochum, Germany. ⟨hal-00853724⟩
121 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More