arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

SpiderSapien:以客户端为中心的网络爬虫与安全扫描器

SpiderSapien: Client-Centric Web Crawler and Security Scanner

Eric Olsson, Benjamin Eriksson, Adam Doupé, Andrei Sabelfeld

arXiv 2609.02532首次发表:更新:

发表机构

Chalmers University of Technology; University of Gothenburg; Arizona State University(查尔姆斯理工大学; 哥德堡大学; 亚利桑那州立大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

SpiderSapien是一款以客户端为中心的网络爬虫与安全扫描器,通过结合可交互元素检测、UI交互排序及LLM表单解决等技术,大幅提升了网络应用的代码覆盖率与XSS漏洞检测能力。

AI 中文摘要

黑盒网络应用爬取与扫描对网络应用的安全测试至关重要,但现有最先进的扫描器无法解决现代网络应用的关键特性:其客户端的极强动态性与交互性。本文将沉浸式交互识别为扫描器深度探索现代网络应用的关键要素,提出了以客户端为中心的爬虫与安全扫描器SpiderSapien。该工具结合了网络应用面向用户的高级反馈通道,以在黑盒爬取循环中实现沉浸式交互,这些反馈通道包括检测可交互元素的新方法、合理排序UI交互,以及利用大语言模型(LLM)解决表单问题。通过上述设计,我们展示了如何可靠地发现并测试现代网络应用的深层状态,此外,其模块化方法与实用抽象层可作为未来扫描器的构建模块。评估结果显示,与现有工作相比,该方法在代码覆盖率和漏洞检测方面均有显著提升:相较于其他任何扫描器,该方法将应用的平均代码覆盖率至少提高了46%;相较于所有其他扫描器的组合,平均代码覆盖率也提高了16%。此外,该方法在7个网络应用中发现了跨站脚本(XSS)漏洞,而其他任何扫描器最多仅能在2个应用中发现此类漏洞。

英文摘要

Black-box web application crawling and scanning play an important role for security testing of web applications. Yet state-of-the-art scanners fall short of addressing key characteristics of a modern web application: its extreme dynamism and interactivity on the client side. This paper identifies immersive interaction as a key ingredient for scanners to deeply explore modern web applications. We propose SpiderSapien, a client-centric crawler and security scanner. SpiderSapien incorporates a unique combination of high-level, user-facing feedback channels from the web application to achieve immersive interaction in a black-box crawling loop. These feedback channels include both novel methods to detect interactable elements and sensibly order UI interactions, and orthogonally using an LLM to solve forms. In doing so, we demonstrate how to reliably discover and test deep states of modern web applications. Furthermore, our modular approach and useful abstraction layer can serve as a building block for future scanners. The evaluation of our approach shows substantial improvements in both code coverage and vulnerability detection over previous work. Our approach increased average code coverage across applications by at least 46% over any other scanner, or 16% when compared to the union of all other scanners. We find XSS vulnerabilities in 7 web applications, while any other scanner finds XSS in up to 2 applications.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑