Scan Me If You Can: Understanding and Detecting Unwanted Vulnerability Scanning
Xigao Li, Babak Amin Azad, Amir Rahmati, Nick Nikiforakis
Abstract
Web vulnerability scanners (WVS) are an indispensable tool for penetration testers and developers of web applications, allowing them to identify and fix low-hanging vulnerabilities before they are discovered by attackers. Unfortunately, malicious actors leverage the very same tools to identify and exploit vulnerabilities in third-party websites. Existing research in the WVS space is largely concerned with how many vulnerabilities these tools can discover, as opposed to trying to identify the tools themselves when they are used illicitly. In this work, we design a testbed to characterize web vulnerability scanners using browser-based and network-based fingerprinting techniques. We conduct a measurement study over 12 web vulnerability scanners as well as 159 users who were recruited to interact with the same web applications that were targeted by the evaluated WVSs. By contrasting the traffic and behavior of these two groups, we discover tool-specific and type-specific behaviors in WVSs that are absent from regular users. Based on these observations, we design and build ScannerScope, a machine-learning-based, web vulnerability scanner detection system. ScannerScope consists of a transparent reverse proxy that injects fingerprinting modules on the fly without the assistance (or knowledge) of the protected web applications. Our evaluation results show that ScannerScope can effectively detect WVSs and protect web applications against unwanted vulnerability scanning, with a detection accuracy of over 99% combined with near-zero false positives on human-visitor traffic. Finally, we show that the asynchronous design of Scanner-Scope results in a negligible impact on server performance and demonstrate that its classifier can resist adversarial ML attacks launched by sophisticated adversaries.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7a3cf883-4022-45a2-961f-2b0de0c5eadaCited by top-tier papers2
- Exploring and Exploiting Security Vulnerabilities in Self-Hosted LLM ServicesZhihuang Liu, Ling Hu, Yonghao Tang, Tongqing Zhou et al.WWW 2026
- Preventing Artificially Inflated SMS Attacks through Large-Scale Traffic InspectionJun Ho Huh, Hyejin Shin, Sunwoo Ahn, Hayoon Yi et al.USENIX Security 2025
Builds on5
- Fingerprinting the Fingerprinters: Learning to Detect Browser Fingerprinting BehaviorsUmar Iqbal, Steven Englehardt, Zubair ShafiqS&P 2021 · 143 citations
- Throwing Darts in the Dark? Detecting Bots with Limited Data using Neural Data AugmentationSteve T. K. Jan, Qingying Hao, Tianrui Hu, Jiameng Pu et al.S&P 2020 · 88 citations
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 65 citations
- Good Bot, Bad Bot: Characterizing Automated Browsing ActivityXigao Li, Babak Amin Azad, Amir Rahmati, Nick NikiforakisS&P 2021 · 45 citations
- Catching Transparent Phish: Analyzing and Detecting MITM Phishing ToolkitsBrian Kondracki, Babak Amin Azad, Oleksii Starov, Nick NikiforakisCCS 2021 · 37 citations
Related papers
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 59 citations
- Smudged Fingerprints: Characterizing and Improving the Performance of Web Application FingerprintingBrian Kondracki, Nick NikiforakisUSENIX Security 2024 · 4 citations
- NeuroScope: Reverse Engineering Deep Neural Network on Edge Devices using Dynamic AnalysisRuoyu Wu, Muqi Zou, Arslan Khan, Taegyu Kim et al.USENIX Security 2025
- YuraScanner: Leveraging LLMs for Task-driven Web App ScanningAleksei Stafeev, Tim Recktenwald, Gianluca De Stefano, Soheil Khodayari et al.NDSS 2025
- ReScan: A Middleware Framework for Realistic and Robust Black-box Web Application ScanningKostas Drakonakis, Sotiris Ioannidis, Jason PolakisNDSS 2023
