Search arXiv⌕ Search

arXiv subjects

Elias Athanasopoulos

Publications and source records attributed to Elias Athanasopoulos.

2 recordsLinked to original sources

TraceLib: System-Call Bitmap Feedback Mechanism for Language-Agnostic Web Fuzzing

Coverage feedback is an important source of guidance for fuzzing. However, obtaining such feedback normally requires application-level instrumentation that is specific to the language and runtime of the application. Given that modern web applications span multiple languages and runtimes, this application-level instrumentation is costly to implement and maintain. Therefore, we present TraceLib, a system-call feedback mechanism for enabling language-agnostic web fuzzing. Our proposed approach observes the transitions of system calls, enriches selected transitions with bounded argument hashes, and converts them into a 65,536-position AFL-like bitmap. By using the generated bitmap, any web fuzzer can decide whether to retain requests that add previously unseen bitmap positions without consulting application code coverage. We integrate TraceLib into WebFuzz and evaluate it under five WebFuzz feedback modes: the two proposed TraceLib variants (one over every traced system call and one projected onto monitored file paths and recognized SQL buffers), the N-gram comparator adapted from Xiao et al. representing the most recent work to our knowledge, WebFuzz's Native grey-box feedback, and black-box fuzzing without feedback. We evaluate TraceLib on sixteen web applications under test (WUTs): eight PHP applications and eight further applications spanning Node.js, Ruby, Java, Go, and Python to demonstrate platform portability. The results show that our proposed TraceLib projected exceeds black-box on all eight PHP WUTs while exceeding Native on four: Joomla, Drupal, PrestaShop, and Bagisto. In addition, measured on an identical replayed request workload, the tracer costs approximately one millisecond of server-side latency per request. These results indicate that compact system-call feedback is a useful runtime-independent proxy for coverage guidance.

cs.SE↗

Fuzzing Frameworks for Server-side Web Applications: A Survey

There are around 5.3 billion Internet users, amounting to 65.7% of the global population, and web technology is the backbone of the services delivered via the Internet. To ensure web applications are free from security-related bugs, web developers test the server-side web applications before deploying them to production. The tests are commonly conducted through the interfaces (i.e., Web API) that the applications expose since they are the entry points to the application. Fuzzing is one of the most promising automated software testing techniques suitable for this task; however, the research on (server-side) web application fuzzing has been rather limited compared to binary fuzzing which is researched extensively. This study reviews the state-of-the-art fuzzing frameworks for testing web applications through web API, identifies open challenges, and gives potential future research. We collect papers from seven online repositories of peer-reviewed articles over the last ten years. Compared to other similar studies, our review focuses more deeply on revealing prior work strategies in generating valid HTTP requests, utilising feedback from the Web Under Tests (WUTs), and expanding input spaces. The findings of this survey indicate that several crucial challenges need to be solved, such as the ineffectiveness of web instrumentation and the complexity of handling microservice applications. Furthermore, some potential research directions are also provided, such as fuzzing for web client programming. Ultimately, this paper aims to give a good starting point for developing a better web fuzzing framework.

cs.SE↗