Authors
Jason Bau, Elie Bursztein, Divij Gupta, John Mitchell
Publication date
2010/5/16
Source
2010 IEEE symposium on security and privacy
Pages
332-345
Publisher
IEEE
Description
Black-box web application vulnerability scanners are automated tools that probe web applications for security vulnerabilities. In order to assess the current state of the art, we obtained access to eight leading tools and carried out a study of: (i) the class of vulnerabilities tested by these scanners, (ii) their effectiveness against target vulnerabilities, and (iii) the relevance of the target vulnerabilities to vulnerabilities found in the wild. To conduct our study we used a custom web application vulnerable to known and projected vulnerabilities, and previous versions of widely used web applications containing known vulnerabilities. Our results show the promise and effectiveness of automated tools, as a group, and also some limitations. In particular, "stored" forms of Cross Site Scripting (XSS) and SQL Injection (SQLI) vulnerabilities are not currently found by many tools. Because our goal is to assess the potential of future …
Total citations
20102011201220132014201520162017201820192020202120222023202411223946523343305344432925292
Scholar articles
J Bau, E Bursztein, D Gupta, J Mitchell - 2010 IEEE symposium on security and privacy, 2010