Adaptive Random Testing for XSS Vulnerability
At a glance
- Citations
- 11
- References
- 23
- Comments
- 0
Abstract
XSS is one of the common vulnerabilities in web applications. Many black-box testing tools may collect a large number of payloads and traverse them to find a payload that can be successfully injected, but they are not very efficient. And previous research has paid less attention to how to improve the efficiency of black-box testing to detect XSS vulnerability. To improve the efficiency of testing, we develop an XSS testing tool. It collects 6128 payloads and uses a headless browser to detect XSS vulnerability. The tool can discover XSS vulnerability quickly with the ART(Adaptive Random Testing) method. We conduct an experiment using 3 extensively adopted open source vulnerable benchmarks and 2 actual websites to evaluate the ART method. The experimental results indicate that the ART method can effectively improve the fuzzing method by more than 27.1% in reducing the number of attempts before accomplishing a successful injection.
Publication details
- DOI
- 10.1109/apsec48747.2019.00018
- OpenAlex
- W2998170209
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.