An Empirical Evaluation of the Effectiveness of Spider and Proxy Modes for Web Security Testing

Kuan Wei Chiu, Shih Sheng Yang, Shin Jie Lee, Wen Tin Lee

研究成果: Conference contribution

摘要

Spider and proxy modes are two commonly employed methods supported by dynamic application security testing (DAST) software. Despite efforts to enhance the automated spider's efficiency, deep exploration of web applications is still constrained by the need for manual intervention in certain complex UI operations. In this regard, the proxy mode serves a crucial intermediary, intercepting and inspecting request messages exchanged between the browser and the web application during manual or scripted browsing activities. This study aims to assess the efficacy of these two modes in terms of code coverage and the number of requests, utilizing two popular PHP-based open-source web applications. The experimental findings demonstrate that employing a hybrid mode (Spider-Last) yields a significant improvement compared to using the spider or proxy mode independently.

原文English
主出版物標題Proceedings - 2023 10th International Conference on Dependable Systems and Their Applications, DSA 2023
發行者Institute of Electrical and Electronics Engineers Inc.
頁面587-588
頁數2
ISBN(電子)9798350304770
DOIs
出版狀態Published - 2023
事件10th International Conference on Dependable Systems and Their Applications, DSA 2023 - Tokyo, Japan
持續時間: 2023 8月 102023 8月 11

出版系列

名字Proceedings - 2023 10th International Conference on Dependable Systems and Their Applications, DSA 2023

Conference

Conference10th International Conference on Dependable Systems and Their Applications, DSA 2023
國家/地區Japan
城市Tokyo
期間23-08-1023-08-11

All Science Journal Classification (ASJC) codes

  • 人工智慧
  • 電腦網路與通信
  • 電腦科學應用
  • 軟體
  • 資訊系統
  • 安全、風險、可靠性和品質

指紋

深入研究「An Empirical Evaluation of the Effectiveness of Spider and Proxy Modes for Web Security Testing」主題。共同形成了獨特的指紋。

引用此