Publication | Open Access
A Clustering Approach for Web Vulnerabilities Detection
30
Citations
16
References
2011
Year
Unknown Venue
EngineeringInformation SecuritySql InjectionsSoftware EngineeringSecurity EvaluationSoftware AnalysisVulnerability AnalysisVulnerability Assessment (Computing)Data MiningClustering ApproachThreat DetectionSecurity TestingKnowledge DiscoveryComputer ScienceNew AlgorithmSecurity Testing MethodVulnerability AssessmentSoftware SecurityProgram AnalysisSoftware TestingVulnerability Discovery
This paper presents a new algorithm aimed at the vulnerability assessment of web applications following a black-box approach. The objective is to improve the detection efficiency of existing vulnerability scanners and to move a step forward toward the automation of this process. Our approach covers various types of vulnerabilities but this paper mainly focuses on SQL injections. The proposed algorithm is based on the automatic classification of the responses returned by the web servers using data clustering techniques and provides especially crafted inputs that lead to successful attacks when vulnerabilities are present. Experimental results on several vulnerable applications and comparative analysis with some existing tools confirm the effectiveness of our approach.
| Year | Citations | |
|---|---|---|
Page 1
Page 1