Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement Learning
Soyoung Lee, Seongil Wi, Sooel Son
Abstract
Black-box web scanners have been a prevalent means of performing penetration testing to find reflected cross-site scripting (XSS) vulnerabilities. Unfortunately, off-the-shelf black-box web scanners suffer from unscalable testing as well as false negatives that stem from a testing strategy that employs fixed attack payloads, thus disregarding the exploitation of contexts to trigger vulnerabilities. To this end, we propose a novel method of adapting attack payloads to a target reflected XSS vulnerability using reinforcement learning (RL). We present Link, a general RL framework whose states, actions, and a reward function are designed to find reflected XSS vulnerabilities in a black-box and fully automatic manner. Link finds 45, 213, and 60 vulnerabilities with no false positives in Firing-Range, OWASP, and WAVSEP benchmarks, respectively, outperforming state-of-the-art web scanners in terms of finding vulnerabilities and ending testing campaigns earlier. Link also finds 43 vulnerabilities in 12 real-world applications, demonstrating the promising efficacy of using RL in finding reflected XSS vulnerabilities. CCS CONCEPTS • Security and privacy → Web application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 47f2b287-7a9e-4b42-9c72-d45a9e047005Cited by top-tier papers8
- Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web ApplicationsEnze Wang, Jianjun Chen, Wei Xie, Chuhan Wang et al.S&P 2024 · 15 citations
- RecurScan: Detecting Recurring Vulnerabilities in PHP Web ApplicationsYoukun Shi, Yuan Zhang, Tianhao Bai, Lei Zhang et al.WWW 2024 · 12 citations
- Dancer in the Dark: Synthesizing and Evaluating Polyglots for Blind Cross-Site ScriptingRobin Kirchner, Jonas Möller, Marius Musch, David Klein et al.USENIX Security 2024 · 9 citations
- SoK: The Pitfalls of Deep Reinforcement Learning for CybersecurityShae McFadden, Myles Foley, Elizabeth Bates, Ilias Tsingenopoulos et al.USENIX Security 2026 · 7 citations
- Anota: Identifying Business Logic Vulnerabilities via Annotation-Based SanitizationMeng Wang, Philipp Görz, Joschua Schilling, Keno Hassler et al.NDSS 2026 · 4 citations
Builds on5
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 85 citations
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 65 citations
- Chainsaw: Chained Automated Workflow-based Exploit GenerationAbeer Alhuzali, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2016 · 52 citations
- On the Feasibility of Automated Built-in Function Modeling for PHP Symbolic ExecutionPenghui Li, Wei Meng, Kangjie Lu, Changhua LuoWWW 2021 · 18 citations
- SquirRL: Automating Attack Analysis on Blockchain Incentive Mechanisms with Deep Reinforcement LearningCharlie Hou, Mingxun Zhou, Yan Ji, Phil Daian et al.NDSS 2021
Related papers
- SQIRL: Grey-Box Detection of SQL Injection Vulnerabilities Using Reinforcement LearningSalim Al Wahaibi, Myles Foley, Sergio MaffeisUSENIX Security 2023
- ReScan: A Middleware Framework for Realistic and Robust Black-box Web Application ScanningKostas Drakonakis, Sotiris Ioannidis, Jason PolakisNDSS 2023
- AdvAgent: Controllable Blackbox Red-teaming on Web AgentsChejian Xu, Mintong Kang, Jiawei Zhang, Zeyi Liao et al.ICML 2025
- YuraScanner: Leveraging LLMs for Task-driven Web App ScanningAleksei Stafeev, Tim Recktenwald, Gianluca De Stefano, Soheil Khodayari et al.NDSS 2025
- Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection VulnerabilitiesErik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel et al.S&P 2023
