Computer and Modernization

Previous Articles     Next Articles

Web Application Vulnerabilities Mining Method Based on Improved Fuzzing

  

  1. (Institute 706, Second Research Academy of CASIC, Beijing 100854, China)
  • Received:2016-02-23 Online:2016-08-18 Published:2016-08-11

Abstract: To solve the problems that slower speed and fewer number of vulnerabilities found of Web fuzzing for mining vulnerabilities, a method to improve the generation of vectors of Web fuzzing is proposed. On the basis of the structure of commonly-used fuzzing for Web application (Web fuzzing) and the analyses of the current methods of testing vectors generation, the genetic algorithm to improve testing vector generation of Web fuzzing is applied. Based on this method, a XSS fuzzing tool is implemented. The testing results of multiple Web applications with XSS fuzzing tool and that with current fuzzing tool are compared, which indicates that the efficiency of mining vulnerability is increased with the method.

Key words: Web security, Web vulnerability, fuzzing, genetic algorithm, test vector

CLC Number: