Lune

USENIX Security2023顶会

SQIRL: Grey-Box Detection of SQL Injection Vulnerabilities Using Reinforcement Learning

Salim Al Wahaibi, Myles Foley, Sergio Maffeis

出版方
2023年份
5顶会引用

摘要

Web security scanners are used to discover SQL injection vulnerabilities in deployed web applications. Scanners tend to use static rules to cover the most common injection cases, missing diversity in their payloads, leading to a high volume of requests and false negatives. Moreover, scanners often rely on the presence of error messages or other significant feedback on the target web pages, as a result of additional insecure programming practices by web developers. In this paper we develop SQIRL, a novel approach to detecting SQL injection vulnerabilities based on deep reinforcement learning, using multiple worker agents and grey-box feedback. Each worker intelligently fuzzes the input fields discovered by an automated crawling component. This approach generates a more varied set of payloads than existing scanners, leading to the discovery of more vulnerabilities. Moreover, SQIRL attempts fewer payloads, because they are generated in a targeted fashion. SQIRL finds all vulnerabilities in our microbenchmark for SQL injection, with substantially fewer requests than most of the state-of-the-art scanners compared with. It also significantly outperforms other scanners on a set of 14 production grade web applications, discovering 33 vulnerabilities, with zero false positives. We have responsibly disclosed 22 novel vulnerabilities found by SQIRL, grouped in 6 CVEs. Table 1: A: SQLi payload (highlighted in pink ) escaping its SQL context to cause the database to pause for 1 second. B-D: SQL queries showing 13 semantically different positions where user input can occur. E: current WordPress example of dangerous parameterised query pattern. A: SELECT * FROM tab WHERE val = ' ' AND SLEEP(1) --' B: SELECT input_1 FROM input_2 WHERE input_3 = 'input_4' GROUP BY 'input_5' C: UPDATE input_6 SET (" input_7 " , " input_8 ") D: INSERT INTO input_9 ( input_10 , input_11 ) SET ('input_12', 'input_13')

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext e48d062a-094e-4bef-8fbf-5c28d4a47dd5

引用它的顶会 Paper5

问问它们各自怎么用它

它引用的顶会 Paper1

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖