Attack Patterns for Black-Box Security Testing of Multi-Party Web Applications
Avinash Sudhodanan, Alessandro Armando, Roberto Carbone, Luca Compagna
摘要
The advent of Software-as-a-Service (SaaS) has led to the development of multi-party web applications (MPWAs). MPWAs rely on core trusted third-party systems (e.g., payment servers, identity providers) and protocols such as Cashier-as-a-Service (CaaS), Single Sign-On (SSO) to deliver business services to users. Motivated by the large number of attacks discovered against MPWAs and by the lack of a single general-purpose application-agnostic technique to support their discovery, we propose an automatic technique based on attack patterns for black-box, security testing of MPWAs. Our approach stems from the observation that attacks against popular MPWAs share a number of similarities, even if the underlying protocols and services are different. In this paper, we target six different replay attacks, a login CSRF attack and a persistent XSS attack. Firstly, we propose a methodology in which security experts can create attack patterns from known attacks. Secondly, we present a security testing framework that leverages attack patterns to automatically generate test cases for testing the security of MPWAs. We implemented our ideas on top of OWASP ZAP (a popular, open-source penetration testing tool), created seven attack patterns that correspond to thirteen prominent attacks from the literature and discovered twenty one previously unknown vulnerabilities in prominent MPWAs (e.g., twitter.com, developer.linkedin.com, pinterest.com), including MPWAs that do not belong to SSO and CaaS families. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Mobile Application Web API Reconnaissance: Web-to-Mobile Inconsistencies & VulnerabilitiesAbner Mendoza, Guofei GuS&P 2018 · 被引用 43 次
- Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On DeploymentsMohammad Ghasemisharif, Chris Kanich, Jason PolakisS&P 2022 · 被引用 25 次
- Finding client-side business flow tampering vulnerabilitiesI Luk Kim, Yunhui Zheng, Hogun Park, Weihang Wang 等ICSE 2020 · 被引用 14 次
- All Your Shops Are Belong to Us: Security Weaknesses in E-commerce PlatformsRohan Pagey, Mohammad Mannan, Amr M. YoussefWWW 2023 · 被引用 10 次
- Messy States of Wiring: Vulnerabilities in Emerging Personal Payment SystemsJiadong Lou, Xu Yuan, Ning ZhangUSENIX Security 2021 · 被引用 4 次
相关 Paper
- Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App EcosystemYizhe Shi, Zhemin Yang, Yifan Yang, Yunteng Yang 等S&P 2026
- Detecting Taint-Style Vulnerabilities in Microservice-Structured Web ApplicationsFengyu Liu, Yuan Zhang, Tian Chen, Youkun Shi 等S&P 2025
- Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web ApplicationsEnze Wang, Jianjun Chen, Wei Xie, Chuhan Wang 等S&P 2024 · 被引用 15 次
- Deemon: Detecting CSRF with Dynamic Analysis and Property GraphsGiancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes 等CCS 2017 · 被引用 74 次
- Automated Black-Box Testing of Mass Assignment Vulnerabilities in RESTful APIsDavide Corradini, Michele Pasqua, Mariano CeccatoICSE 2023 · 被引用 12 次
