DetLogic: A black-box approach for detecting logic vulnerabilities in web applications. (1st May 2018)
- Record Type:
- Journal Article
- Title:
- DetLogic: A black-box approach for detecting logic vulnerabilities in web applications. (1st May 2018)
- Main Title:
- DetLogic: A black-box approach for detecting logic vulnerabilities in web applications
- Authors:
- Deepa, G.
Thilagam, P. Santhi
Praseed, Amit
Pais, Alwyn R. - Abstract:
- Abstract: Web applications are subject to attacks by malicious users owing to the fact that the applications are implemented by software developers with insufficient knowledge about secure programming. The implementation flaws arising due to insecure coding practices allow attackers to exploit the application in order to perform adverse actions leading to undesirable consequences. These flaws can be categorized into injection and logic flaws. As large number of tools and solutions are available for addressing injection flaws, the focus of the attackers is shifting towards exploitation of logic flaws. The logic flaws allow attackers to compromise the application-specific functionality against the expectations of the stakeholders, and hence it is important to identify these flaws in order to avoid exploitation. Therefore, a prototype calledDetLogic is developed for detecting different types of logic vulnerabilities such as parameter manipulation, access-control, and workflow bypass vulnerabilities in web applications. DetLogic employs black-box approach, and models the intended behavior of the application as an annotated finite state machine, which is subsequently used for deriving constraints related to input parameters, access-control, and workflows. The derived constraints are violated for simulating attack vectors to identify the vulnerabilities. DetLogic is evaluated against benchmark applications and is found to work effectively.
- Is Part Of:
- Journal of network and computer applications. Volume 109(2018)
- Journal:
- Journal of network and computer applications
- Issue:
- Volume 109(2018)
- Issue Display:
- Volume 109, Issue 2018 (2018)
- Year:
- 2018
- Volume:
- 109
- Issue:
- 2018
- Issue Sort Value:
- 2018-0109-2018-0000
- Page Start:
- 89
- Page End:
- 109
- Publication Date:
- 2018-05-01
- Subjects:
- Application logic vulnerabilities -- Logic attacks -- Web application security -- Parameter tampering -- State violation -- Workflow violation -- Sequence violation -- Authorization bypass -- Authentication bypass
Microcomputers -- Periodicals
Computer networks -- Periodicals
Application software -- Periodicals
Micro-ordinateurs -- Périodiques
Réseaux d'ordinateurs -- Périodiques
Logiciels d'application -- Périodiques
Application software
Computer networks
Microcomputers
Periodicals
004.05
004 - Journal URLs:
- http://www.sciencedirect.com/science/journal/10848045 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.jnca.2018.01.008 ↗
- Languages:
- English
- ISSNs:
- 1084-8045
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 5021.410600
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 6415.xml