WSFAggressor: an extensible web service framework attacking tool

  • Authors:
  • Rui André Oliveira;Nuno Laranjeiro;Marco Vieira

  • Affiliations:
  • University of Coimbra, Coimbra, Portugal;University of Coimbra, Coimbra, Portugal;University of Coimbra, Coimbra, Portugal

  • Venue:
  • Proceedings of the Industrial Track of the 13th ACM/IFIP/USENIX International Middleware Conference
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents a tool for testing the security of web service frameworks. The tool implements a large set of attack types, defined based on previous security research studies, existing testing tools, and field experience. The motivation is that developers frequently build web services based on the assumption that the underlying frameworks are secure, which is not always the case. Despite the evident need for security in the platforms that support services, existing security testing tools are very limited. In practice, most tools focus on application level vulnerabilities, and the few that allow testing platforms implement a very limited set of attack types. To the best of our knowledge, our tool includes more attacks than any other existing tool. Furthermore, by implementing an extensible architecture (based on plug-ins), the tool can be easily extended with additional attacks, supporting also a large variety of testing configurations. Results show that it can be used to disclose critical security problems in well-known frameworks.