Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/2523514.2523589acmotherconferencesArticle/Chapter ViewAbstractPublication PagessinConference Proceedingsconference-collections
tutorial

Security vulnerabilities and mitigation techniques of web applications

Published: 26 November 2013 Publication History
  • Get Citation Alerts
  • Abstract

    Web applications contain vulnerabilities, which may lead to serious security breaches such as stealing of confidential information. To protect against security breaches, it is necessary to understand the detailed steps of attacks and the pros and cons of existing defense mechanisms. This tutorial provides an overview of four web application security vulnerabilities: SQL injection, Cross-Site Scripting, Cross-Site Request Forgery, and clickjacking. Then it discusses two popular mitigation approaches: security testing and monitoring. The tutorial is intended to enable practitioners for choosing the right technique to defend against web application security vulnerabilities.

    References

    [1]
    J. Grossman, How does your website security stack up against peers? White Hat Report, Summer 2012, Accessed from https://www.whitehatsec.com/assets/WPstats_summer12_12th.pdf
    [2]
    Application Vulnerability Trend Report, CEZNIC White paper, 2013, Accessed from http://info.cenzic.com/rs/cenzic/images/Cenzic-Application-Vulnerability-Trends-Report-2013.pdf
    [3]
    SQL Injection, https://www.owasp.org/index.php/SQL_Injection
    [4]
    XSS, https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)
    [5]
    Cross-Site Request forgery, https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF).
    [6]
    Clickjacking, https://www.owasp.org/index.php/Clickjacking
    [7]
    H. Shahriar, S. North, and W. Chen, "Early Detection of SQL Injection Attacks," International Journal of Network Security & Its Applications (IJNSA), Vol. 5, No. 4, July 2013, pp. 53--65.
    [8]
    H. Shahriar, V. Devendran, and H. Haddad, "ProClick: A Framework for Testing Clickjacking Attacks in Web Applications," Proc. of 6th ACM/SIGSAC International Conference on Security of Information and Networks (SIN 2013), Aksaray, Turkey, November 2013, 8 pp. (to appear).
    [9]
    H. Shahriar and M. Zulkernine, "S2XS2: A Server Side Approach to Automatically Detect XSS Attacks," Proc. of the 9th IEEE International Conference on Dependable, Autonomic and Secure Computing (DASC), Sydney, Australia, December 2011, pp. 7--14.
    [10]
    H. Shahriar and M. Zulkernine, "Client-Side Detection of Cross-Site Request Forgery Attacks," Proc. of the 21st IEEE International Symposium on Software Reliability Engineering (ISSRE), San Jose, USA, November 2010, pp. 358--367.
    [11]
    H. Shahriar and M. Zulkernine, "Mitigation of Program Security Vulnerabilities: Approaches and Challenges," ACM Computing Surveys, Vol. 44, No. 3, Article 11, pp. 1--46, May 2012.

    Cited By

    View all
    • (2023)ReconMaster: A CLI Based Web Reconnaissance Tool2023 IEEE International Conference on ICT in Business Industry & Government (ICTBIG)10.1109/ICTBIG59752.2023.10455983(1-5)Online publication date: 8-Dec-2023

    Recommendations

    Comments

    Information & Contributors

    Information

    Published In

    cover image ACM Other conferences
    SIN '13: Proceedings of the 6th International Conference on Security of Information and Networks
    November 2013
    483 pages
    ISBN:9781450324984
    DOI:10.1145/2523514
    Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

    Sponsors

    • Macquarie U., Austarlia
    • MNIT: Malaviya National Institute of Technology
    • Aksaray Univ.: Aksaray University
    • SFedU: Southern Federal University

    In-Cooperation

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    Published: 26 November 2013

    Check for updates

    Author Tags

    1. CSRF
    2. SQL injection
    3. XSS
    4. clickjacking
    5. monitoring
    6. security testing
    7. web security

    Qualifiers

    • Tutorial

    Conference

    SIN '13
    Sponsor:
    • MNIT
    • Aksaray Univ.
    • SFedU

    Acceptance Rates

    Overall Acceptance Rate 102 of 289 submissions, 35%

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • Downloads (Last 12 months)23
    • Downloads (Last 6 weeks)1
    Reflects downloads up to 11 Aug 2024

    Other Metrics

    Citations

    Cited By

    View all
    • (2023)ReconMaster: A CLI Based Web Reconnaissance Tool2023 IEEE International Conference on ICT in Business Industry & Government (ICTBIG)10.1109/ICTBIG59752.2023.10455983(1-5)Online publication date: 8-Dec-2023

    View Options

    Get Access

    Login options

    View options

    PDF

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader

    Media

    Figures

    Other

    Tables

    Share

    Share

    Share this Publication link

    Share on social media