Detecting Common Injection-Based Vulnerabilities in Web-Applications
Annotatsiya
The research paper showcases a general method of detecting injection based vulnerabilities in the web applications. These type of vulnerabilities allows the attackers to manipulate various parameters leading to theft of data, identity fraud as well as system compromise. The key types of injections include SQL Injection, Cross-Site Scripting XSS and Command Injection. The currently available tools often fail to detect all three of these or are too costly. The technique mentioned herein the paper detects all these injection flaws by comparing both the application’s response as well as the behaviour before and after sending a crafted payload. By conducting experiments on multiple vulnerable web apps it was seen that our method outperforms both open-source tools as well as rivals that of commercial ones and thus achieving broad detection coverage with very few false positives.
Hali tarjima qilinmagan