Smudged Fingerprints: Characterizing and Improving the Performance of Web Application Fingerprinting
Brian Kondracki, Nick Nikiforakis
摘要
Open-source web applications have given everyone the ability to deploy complex web applications on their site(s), ranging from blogs and personal clouds, to server administration tools and webmail clients. Given that there exists millions of deployments of this software in the wild, the ability to fingerprint a particular release of a web application residing at a web endpoint is of interest to both attackers and defenders alike. In this work, we study modern web application fingerprinting techniques and identify their inherent strengths and weaknesses. We design WASABO, a web application testing framework and use it to measure the performance of six web application fingerprinting tools against 1,360 releases of popular web applications. While 94.8% of all web application releases were correctly labeled by at least one fingerprinting tool in ideal conditions, many tools are unable to produce a single version prediction for a particular release. This leads to instances where a release is labeled as multiple disparate versions, resulting in administrator confusion on the security posture of an unknown web application. We also measure the accuracy of each tool against realworld deployments of the studied web applications, observing up to an 80% drop-off in performance compared to our offline results. To identify causes for this performance degradation, as well as to improve the robustness of these tools in the wild, we design a web-application-agnostic middleware which applies a series of transformations to the traffic of each fingerprinting tool. Overall, we are able to improve the performance of popular web application fingerprinting tools by up to 22.9%, without any modification to the evaluated tools.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Beyond Exploit Scanning: A Functional Change-Driven Approach to Remote Software Version IdentificationJinsong Chen, Mengying Wu, Geng Hong, Baichao An 等USENIX Security 2025
- Who's to Blame? Rethinking the Brittleness of Automated Web GUI Testing from a Pragmatic PerspectiveHaonan Zhang, Kundi Yao, Zishuo Ding, Lizhi Liao 等ASE 2025
它引用的顶会 Paper3
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- ReScan: A Middleware Framework for Realistic and Robust Black-box Web Application ScanningKostas Drakonakis, Sotiris Ioannidis, Jason PolakisNDSS 2023
- ChargePrint: A Framework for Internet-Scale Discovery and Security Analysis of EV Charging Management SystemsTony Nasr, Sadegh Torabi, Elias Bou-Harb, Claude Fachkha 等NDSS 2023
相关 Paper
- Scan Me If You Can: Understanding and Detecting Unwanted Vulnerability ScanningXigao Li, Babak Amin Azad, Amir Rahmati, Nick NikiforakisWWW 2023 · 被引用 7 次
- The Great Request Robbery: An Empirical Study of Client-side Request Hijacking Vulnerabilities on the WebSoheil Khodayari, Thomas Barber, Giancarlo PellegrinoS&P 2024 · 被引用 12 次
- Large-Scale Measurement and Real-World Mitigation of Web Browser Fingerprinting in the WildTom Ritter, Fatih Kilic, Frederik Braun, Elisa Luo 等CCS 2026
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood 等USENIX Security 2024 · 被引用 16 次
- k-fingerprinting: A Robust Scalable Website Fingerprinting TechniqueJamie Hayes, George DanezisUSENIX Security 2016 · 被引用 474 次
