Please use this identifier to cite or link to this item: https://doi.org/10.21256/zhaw-21946
Full metadata record
DC FieldValueLanguage
dc.contributor.authorKushnir, Malte-
dc.contributor.authorFavre, Olivier-
dc.contributor.authorRennhard, Marc-
dc.contributor.authorEsposito, Damiano-
dc.contributor.authorZahnd, Valentin-
dc.date.accessioned2021-03-08T08:31:10Z-
dc.date.available2021-03-08T08:31:10Z-
dc.date.issued2021-
dc.identifier.isbn978-989-758-491-6de_CH
dc.identifier.urihttps://digitalcollection.zhaw.ch/handle/11475/21946-
dc.description.abstractAutomated and reproducible security testing of web applications is getting more and more important, driven by short software development cycles and constraints with respect to time and budget. Some types of vulnerabilities can already be detected reasonably well by automated security scanners, e.g., SQL injection or cross-site scripting vulnerabilities. However, other types of vulnerabilities are much harder to uncover in an automated way. This includes access control vulnerabilities, which are highly relevant in practice as they can grant unauthorized users access to security-critical data or functions in web applications. In this paper, a practical solution to automatically detect access control vulnerabilities in the context of HTTP GET requests is presented. The solution is based on previously proposed ideas, which are extended with novel approaches to enable completely automated access control testing with minimal configuration effort that enables frequent and reproducible testing. An evaluation using four web applications based on different technologies demonstrates the general applicability of the solution and that it can automatically uncover most access control vulnerabilities while keeping the number of false positives relatively low.de_CH
dc.language.isoende_CH
dc.publisherSciTePressde_CH
dc.rightshttp://creativecommons.org/licenses/by-nc-nd/4.0/de_CH
dc.subjectAutomated web application security testingde_CH
dc.subjectAccess control security testingde_CH
dc.subjectBlack box security testingde_CH
dc.subject.ddc005: Computerprogrammierung, Programme und Datende_CH
dc.titleAutomated black box detection of HTTP GET request-based access control vulnerabilities in web applicationsde_CH
dc.typeKonferenz: Paperde_CH
dcterms.typeTextde_CH
zhaw.departementSchool of Engineeringde_CH
zhaw.organisationalunitInstitut für Informatik (InIT)de_CH
dc.identifier.doi10.5220/0010300102040216de_CH
dc.identifier.doi10.21256/zhaw-21946-
zhaw.conference.detailsICISSP 2021, online, 11-13 February 2021de_CH
zhaw.funding.euNode_CH
zhaw.originated.zhawYesde_CH
zhaw.pages.end216de_CH
zhaw.pages.start204de_CH
zhaw.publication.statuspublishedVersionde_CH
zhaw.publication.reviewPeer review (Publikation)de_CH
zhaw.title.proceedingsProceedings of the 7th International Conference on Information Systems Security and Privacyde_CH
zhaw.webfeedInformation Securityde_CH
zhaw.funding.zhawscanmeter Next Generationde_CH
zhaw.author.additionalNode_CH
zhaw.display.portraitYesde_CH
Appears in collections:Publikationen School of Engineering

Files in This Item:
File Description SizeFormat 
2021_Kushnir_etal_Automated-black-box-detection_ICISSP.pdf292.85 kBAdobe PDFThumbnail
View/Open
Show simple item record
Kushnir, M., Favre, O., Rennhard, M., Esposito, D., & Zahnd, V. (2021). Automated black box detection of HTTP GET request-based access control vulnerabilities in web applications [Conference paper]. Proceedings of the 7th International Conference on Information Systems Security and Privacy, 204–216. https://doi.org/10.5220/0010300102040216
Kushnir, M. et al. (2021) ‘Automated black box detection of HTTP GET request-based access control vulnerabilities in web applications’, in Proceedings of the 7th International Conference on Information Systems Security and Privacy. SciTePress, pp. 204–216. Available at: https://doi.org/10.5220/0010300102040216.
M. Kushnir, O. Favre, M. Rennhard, D. Esposito, and V. Zahnd, “Automated black box detection of HTTP GET request-based access control vulnerabilities in web applications,” in Proceedings of the 7th International Conference on Information Systems Security and Privacy, 2021, pp. 204–216. doi: 10.5220/0010300102040216.
KUSHNIR, Malte, Olivier FAVRE, Marc RENNHARD, Damiano ESPOSITO und Valentin ZAHND, 2021. Automated black box detection of HTTP GET request-based access control vulnerabilities in web applications. In: Proceedings of the 7th International Conference on Information Systems Security and Privacy. Conference paper. SciTePress. 2021. S. 204–216. ISBN 978-989-758-491-6
Kushnir, Malte, Olivier Favre, Marc Rennhard, Damiano Esposito, and Valentin Zahnd. 2021. “Automated Black Box Detection of HTTP GET Request-Based Access Control Vulnerabilities in Web Applications.” Conference paper. In Proceedings of the 7th International Conference on Information Systems Security and Privacy, 204–16. SciTePress. https://doi.org/10.5220/0010300102040216.
Kushnir, Malte, et al. “Automated Black Box Detection of HTTP GET Request-Based Access Control Vulnerabilities in Web Applications.” Proceedings of the 7th International Conference on Information Systems Security and Privacy, SciTePress, 2021, pp. 204–16, https://doi.org/10.5220/0010300102040216.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.