Exploiting the potential of web application vulnerability scanning
Autor: | Esposito, Damiano, Rennhard, Marc, Ruf, Lukas, Wagner, Arno |
---|---|
Jazyk: | angličtina |
Rok vydání: | 2018 |
Předmět: |
0202 electrical engineering
electronic engineering information engineering Web application security Vulnerability scanning Vulnerability detection performance 020207 software engineering 020201 artificial intelligence & image processing 02 engineering and technology 005: Computerprogrammierung Programme und Daten |
Popis: | Using automated web application vulnerability scanners so that they truly live up to their potential is difficult. Two of the main reasons for this are limitations with respect to crawling capabilities and problems to perform authenticated scans. In this paper, we present JARVIS, which provides technical solutions that can be applied to a wide range of vulnerability scanners to overcome these limitations. Our evaluation shows that by using JARVIS, the vulnerability detection performance of five freely available scanners can be improved by more than 100% compared to using them in their basic configuration. As the configuration effort to use JARVIS is small and the configurations are scanner-independent, JARVIS also allows to use multiple scanners in parallel in an efficient way. In an additional evaluation, we therefore analyzed the potential and limitations of using multiple scanners in parallel. This revealed that using multiple scanners in a reasonable way is indeed beneficial as it increases the number of detected vulnerabilities without a significant negative impact on the reported false positives. |
Databáze: | OpenAIRE |
Externí odkaz: |