ReScan: A Middleware Framework for Realistic and Robust Black-box Web Application Scanning

ReScan: A Middleware Framework for Realistic and Robust Black-box Web Application Scanning
复制标题

DOI:
10.14722/ndss.2023.24169
复制
发表时间:
2023
期刊:
Proceedings 2023 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Kostas Drakonakis;S. Ioannidis;Jason Polakis
Kostas Drakonakis;S. Ioannidis;Jason Polakis
中科院分区:
其他
文献类型:
--
作者:
Kostas Drakonakis;S. Ioannidis;Jason Polakis

文献摘要

相似文献

黑盒Web漏洞扫描器对于安全研究人员和从业人员来说是非常宝贵的。尽管最近的方法解决了扫描仪的一些固有局限性,但许多方法还没有充分地与Web浏览器和应用程序一起发展,并且通常缺乏处理导航和与现代Web应用程序交互的固有挑战的能力。而不是建立一个替代的扫描仪,自然只能结合有限的一组广泛的可识别性,发现现有的扫描仪提供的众多功能,在本文中,我们提出了一个完全不同的策略。我们提出ReScan,扫描仪不可知的中间件框架,透明地增强扫描仪的功能,通过调解他们的互动与Web应用程序在一个现实的和强大的方式,使用一个精心策划的,完全成熟的现代浏览器。从本质上讲,我们的框架可以与任何漏洞扫描器结合使用,从而使用户能够从现有和未来的扫描器的功能中受益。我们的可扩展和模块化框架包括一系列增强技术,可解决最先进的扫描仪通常面临的限制和障碍。我们的实验评估表明,尽管成熟的浏览器引入了相当大的(和预期的)开销,但我们的框架显着提高了流行扫描仪实现的代码覆盖率(平均168%),导致检测到的反射和存储的XSS漏洞数量分别增加了66%和161%。
—Black-box web vulnerability scanners are invaluable for security researchers and practitioners. Despite recent approaches tackling some of the inherent limitations of scanners, many have not sufficiently evolved alongside web browsers and applications, and often lack the capabilities for handling the inherent challenges of navigating and interacting with modern web applications. Instead of building an alternative scanner that could naturally only incorporate a limited set of the wide range of vulnerability-finding capabilities offered by the multitude of existing scanners, in this paper we propose an entirely different strategy. We present ReScan, a scanner-agnostic middleware framework that transparently enhances scanners’ capabilities by mediating their interaction with web applications in a realistic and robust manner, using an orchestrated, fully-fledged modern browser. In essence, our framework can be used in conjunction with any vulnerability scanner, thus allowing users to benefit from the capabilities of existing and future scanners. Our extensible and modular framework includes a collection of enhancement techniques that address limitations and obstacles commonly faced by state-of-the-art scanners. Our experimental evaluation demonstrates that despite the considerable (and expected) overhead introduced by a fully-fledged browser, our framework significantly improves the code coverage achieved by popular scanners (168% on average), resulting in a 66% and 161% increase in the number of reflected and stored XSS vulnerabilities detected, respectively.