kirancodes.me
To Proof Maintenance & Beyond!

Automated security testing of web widget interactions

Cor-Paul Bezemer, Ali Mesbah, Arie van Deursen

Abstract

We present a technique for automatically detecting security vulnerabilities in client-side self-contained components, called web widgets, that can co-exist independently on a single web page. In this paper we focus on two security scenarios, namely the case in which (1) a malicious widget changes the content (DOM) of another widget, and (2) a widget steals data from another widget and sends it to the server via an HTTP request. We propose a dynamic analysis approach for automatically executing the web application and analyzing the runtime changes in the user interface, as well as the outgoing HTTP calls, to detect inter-widget interaction violations.

BibTeX
@inproceedings{Bezemer-al:FSE09,
  author    = {Cor{-}Paul Bezemer and
               Ali Mesbah and
               Arie van Deursen},
  title     = {Automated security testing of web widget interactions},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {81--90},
  publisher = {{ACM}},
  year      = {2009},
}

Related papers