A Hesitation Step into the BlackBox: Heuristic-Based Web Applications Reverse Engineering - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

A Hesitation Step into the BlackBox: Heuristic-Based Web Applications Reverse Engineering

Résumé

Automated black-box scanners alternatively reverse-engineer and fuzz web applications to detect vulnerabilities. It is established that the knowledge they acquired about such applications plays a key role in their ability to exhibit vulnerabilities. In this talk, we adapt a method to automatically reverse-engineer web applications. Three heuristics drive this process. Empirical experiments show that our method obtains a more precise knowledge of the application than state-of-the-art tools, and also increases vulnerability detection capability.
Fichier non déposé

Dates et versions

hal-00853730 , version 1 (26-08-2013)

Identifiants

  • HAL Id : hal-00853730 , version 1

Citer

Fabien Duchene, Sanjay Rawat, Jean-Luc Richier, Roland Groz. A Hesitation Step into the BlackBox: Heuristic-Based Web Applications Reverse Engineering. NSC 2013 - NoSuchCon Conference, May 2013, Paris, France. ⟨hal-00853730⟩
252 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More