Title
A Search-Based Testing Approach for XML Injection Vulnerabilities in Web Applications
Abstract
In most cases, web applications communicate with web services (SOAP and RESTful). The former act as a front-end to the latter, which contain the business logic. A hacker might not have direct access to those web services (e.g., they are not on public networks), but can still provide malicious inputs to the web application, thus potentially compromising related services. Typical examples are XML injection attacks that target SOAP communications. In this paper, we present a novel, search-based approach used to generate test data for a web application in an attempt to deliver malicious XML messages to web services. Our goal is thus to detect XML injection vulnerabilities in web applications. The proposed approach is evaluated on two studies, including an industrial web application with millions of users. Results show that we are able to effectively generate test data (e.g., input values in an HTML form) that detect such vulnerabilities.
Year
DOI
Venue
2017
10.1109/ICST.2017.39
2017 IEEE International Conference on Software Testing, Verification and Validation (ICST)
Keywords
Field
DocType
security testing,xml injection,sbst
Web API,World Wide Web,Web page,WS-Addressing,Computer science,SOAP,Web modeling,Web application security,Web service,WS-Policy
Conference
ISSN
ISBN
Citations 
2381-2834
978-1-5090-6032-0
2
PageRank 
References 
Authors
0.37
22
4
Name
Order
Citations
PageRank
Sadeeq Jan1121.89
Cu D. Nguyen222414.19
Andrea Arcuri3263092.48
Lionel C. Briand48795481.98