학술논문

Dirmap: Web Application Vulnerability Detection Platform Based on Script Code
Document Type
Conference
Source
2021 IEEE 21st International Conference on Software Quality, Reliability and Security Companion (QRS-C) QRS-C Software Quality, Reliability and Security Companion (QRS-C), 2021 IEEE 21st International Conference on. :148-151 Dec, 2021
Subject
Computing and Processing
Dictionaries
Codes
Data analysis
Conferences
Crawlers
Software quality
Explosions
web application
vulnerability detection
detection platform
information leakage
Language
ISSN
2693-9371
Abstract
Web vulnerability detection technology is a very important approach to detect and ensure security in web application. However, there are limitation associated with the existing web application vulnerability detection methods in terms of variations in the detection capabilities. In this paper, a Script Code-based web application vulnerability detection platform named Dirmap is designed and implemented to address the aforementioned gap. The aim is to accurately and efficiently detect information leakage in existing web applications. The Dirmap (1) provides the web graphical management interface and data analysis display function based on the flash framework; (2) supports four detection patterns, including dictionary detection, pure explosion detection, crawler dynamic dictionary and fuzzy tag detection; (3) provides many functions of recursively scanning options, automatic detection of false leak pages, automatic processing of duplicate results, etc. The experimental results show that Dirmap can accurately and effectively detect information leakage vulnerabilities. Thus, promoting the overall security of web application systems. In addition, prevent hackers from using vulnerabilities to obtain unauthorized information.