Detecting SQL Injection Vulnerabilities in Web Services

被引:19
作者
Antunes, Nuno [1 ]
Vieira, Marco [1 ]
机构
[1] Univ Coimbra, Dept Informat Engn, CISUC, P-3000 Coimbra, Portugal
来源
LADC: 2009 4TH LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE COMPUTING | 2009年
关键词
D O I
10.1109/LADC.2009.21
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Web services are often deployed with critical software bugs that can be maliciously exploited Web vulnerability scanners are regarded as an easy way to test web applications against security vulnerabilities. However, previous research shows that the effectiveness of these tools in web services environments is very poor. In fact, the high number of false-positives and the low coverage observed in practice highlight the strong limitations of these tools. The goal of this paper is to demonstrate that it is possible to develop a vulnerability scanner for web services that performs much better than the commercial ones currently available. Thus, we propose an approach to detect SQL Injection vulnerabilities, one of the most common and most critical types of vulnerabilities in web environments. Experimental evaluation shows that our approach performs much better than well-known commercial tools, achieving very high detection coverage while maintaining the false positives rate quite low.
引用
收藏
页码:17 / 24
页数:8
相关论文
共 15 条
[1]  
Acunetix, 2008, AC WEB VULN SCANN
[2]  
[Anonymous], 2008, HP WebInspect
[3]  
Antunes N, 2009, IEEE IFIP INT C DEP
[4]  
ANTUNES N, 2008, WEB SERVICES VULNERA
[5]  
CHAPPEL DA, 2002, JAVA WEB SERVICES US
[6]  
Fonseca J., 2007, 13 IEEE PAC RIM DEP
[7]  
*FOUNDST, 2008, FOUNDST WSDIGGER
[8]  
Huang Y.-W., 2003, P 12 INT C WORLD WID, P148, DOI [10.1145/775152.775174, DOI 10.1145/775152.775174]
[9]  
*IBM, 2008, IBM RAT APPSCAN
[10]  
*SOAPUI, 2007, EV