Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Authors: Kento Hasegawa ; Seira Hidano and Kazuhide Fukushima

Affiliation: KDDI Research, Inc., 2-1-15, Ohara, Fujimino, Saitama, Japan

Keyword(s): Cross-Site Scripting, Reinforcement Learning, Vulnerability Testing.

Abstract: Cross-site scripting (XSS) is a frequently exploited vulnerability in web applications. Existing XSS testing tools utilize a brute-force or heuristic approach to discover vulnerabilities, which increases the testing time and load of the target system. Reinforcement learning (RL) is expected to decrease the burden on humans and enhance the efficiency of the testing task. This paper proposes a method to automate XSS vulnerability testing using RL. RL is employed to obtain an efficient policy to compose test strings for XSS vulnerabilities. Based on an observed state, an agent composes a test string that exploits an XSS vulnerability and passes the string to a target web page. A training environment XSS Gym is developed to provide a variety of XSS vulnerabilities during training. The proposed method significantly decreases the number of requests to the target web page during the testing process by acquiring an efficient policy with RL. Experimental results demonstrate that the proposed method effectively discovers XSS vulnerabilities with the fewest requests compared to the existing open-source tools. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 70.40.220.129

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Hasegawa, K.; Hidano, S. and Fukushima, K. (2023). Automating XSS Vulnerability Testing Using Reinforcement Learning. In Proceedings of the 9th International Conference on Information Systems Security and Privacy - ICISSP; ISBN 978-989-758-624-8; ISSN 2184-4356, SciTePress, pages 70-80. DOI: 10.5220/0011653600003405

@conference{icissp23,
author={Kento Hasegawa. and Seira Hidano. and Kazuhide Fukushima.},
title={Automating XSS Vulnerability Testing Using Reinforcement Learning},
booktitle={Proceedings of the 9th International Conference on Information Systems Security and Privacy - ICISSP},
year={2023},
pages={70-80},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0011653600003405},
isbn={978-989-758-624-8},
issn={2184-4356},
}

TY - CONF

JO - Proceedings of the 9th International Conference on Information Systems Security and Privacy - ICISSP
TI - Automating XSS Vulnerability Testing Using Reinforcement Learning
SN - 978-989-758-624-8
IS - 2184-4356
AU - Hasegawa, K.
AU - Hidano, S.
AU - Fukushima, K.
PY - 2023
SP - 70
EP - 80
DO - 10.5220/0011653600003405
PB - SciTePress