Загрузка страницы

Andrei Sabelfeld - Next Generation Web Crawling and Security Scanning

Abstract: Securing web applications is a pressing challenge, as manifested by millions of dollars paid in bounties annually by the web’s big players like Google and Meta (Facebook). Web security scanners play an important role, focusing on crawling and scanning for vulnerabilities. Unfortunately, state-of-the-art falls short of deeply exploring web applications, running into roadblocks both on the client- and server-side and failing to track non-trivial data- and control flows in web applications.

This talk illuminates key challenges for crawling and scanning the modern web. To tackle these challenges, we showcase a line of work that 1) develops navigation modelling, page traversing, and tracking inter-page dependencies as the foundation for Next Generation Web Crawling and Scanning; 2) leverages SMT solving to pass input validation while scanning the web; and 3) leverages database-aware fuzzing to find unprotected output. We demonstrate how our approach leads to both boosting the code coverage and discovering new vulnerabilities in production software, including HotCRP, osCommerce, PrestaShop, and WordPress.

The talk is based on the S&P’21, CCS’23, and USENIX’24 papers written jointly with Benjamin Eriksson, Eric Olsson, Giancarlo Pellegrino, Adam Doupé, Amanda Stjerna, Riccardo De Masellis, and Philipp Ruemmer.

Bio: Andrei Sabelfeld is a Chalmers University of Technology Professor and newly appointed part-time Visiting Professor at KTH. Before becoming a faculty member, he was a Research Associate at Cornell University in Ithaca, NY, USA. Andrei Sabelfeld’s research ranges from foundations to practice in various computer security and privacy topics. He has received several prestigious prizes and awards from ERC, SSF, VR, WASP, Chalmers, Google, Meta (Facebook), and Amazon. Today, he leads a group of researchers at Chalmers engaged in many internationally visible projects on software security, web security, IoT security, security foundations, and applied cryptography.

Disclaimer: This video was recorded when the speaker gave a seminar at Digital Futures, a cross-disciplinary research centre that explores and develops digital technologies of great societal importance (https://www.digitalfutures.kth.se). The content is produced by the speaker and not the center. The captions have been generated automatically. If you need refined captions to access the material, please reach out to the Associate Director for Seminars at Digital Futures.

Видео Andrei Sabelfeld - Next Generation Web Crawling and Security Scanning канала Digital Futures: Research Hub for Digitalization
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
22 января 2024 г. 18:09:34
00:51:08
Другие видео канала
Digitalize in Stockholm 2021_Sandvik-panel_Digital shift – Data driven decision makingDigitalize in Stockholm 2021_Sandvik-panel_Digital shift – Data driven decision makingAude G. Billard - Cobots deployment - KEYNOTEAude G. Billard - Cobots deployment - KEYNOTEOptimisation of Agricultural Management for Soil Carbon Sequestration Using Deep - RESEARCH PROJECTOptimisation of Agricultural Management for Soil Carbon Sequestration Using Deep - RESEARCH PROJECTDeyou Zhang - Training Beam Sequence Design for Millimeter Wave Tracking SystemsDeyou Zhang - Training Beam Sequence Design for Millimeter Wave Tracking SystemsPawel Herman - The Computational Cognitive Brain as a Gateway to Study IntelligencePawel Herman - The Computational Cognitive Brain as a Gateway to Study IntelligenceDavid Broman - Domain-specific modeling: equation-based languages and probabilistic programmingDavid Broman - Domain-specific modeling: equation-based languages and probabilistic programmingMarios Polycarpou - Distributed Fault Diagnosis of Interconnected Cyber-Physical SystemsMarios Polycarpou - Distributed Fault Diagnosis of Interconnected Cyber-Physical SystemsJiang Hu - Machine Learning Techniques for Microprocessor Power Modeling and Performance DiagnosisJiang Hu - Machine Learning Techniques for Microprocessor Power Modeling and Performance DiagnosisIntelligence through reasoning - POSTDOC PROJECTIntelligence through reasoning - POSTDOC PROJECTKia Höök - Soma Design – Intertwining Aesthetics, Ethics and MovementKia Höök - Soma Design – Intertwining Aesthetics, Ethics and MovementNguyen Hoang Tran - Federated Learning over Wireless NetworksNguyen Hoang Tran - Federated Learning over Wireless NetworksEmil Björnson - Evolving Mobile Broadband Connectivity Towards 6GEmil Björnson - Evolving Mobile Broadband Connectivity Towards 6GNicolae Paladi - Cooking secrets in leaky cauldrons: promises of confidential computingNicolae Paladi - Cooking secrets in leaky cauldrons: promises of confidential computingPascal Helson - Cortex-wide topography of 1/f-exponent in Parkinson’s diseasePascal Helson - Cortex-wide topography of 1/f-exponent in Parkinson’s diseaseSOS - Empowering User Control over Sensitive IoT Data - RESEARCH PROJECTSOS - Empowering User Control over Sensitive IoT Data - RESEARCH PROJECTOptimized transport through digitalization and electrification 10x - PANEL lead by Scania and XylemOptimized transport through digitalization and electrification 10x - PANEL lead by Scania and XylemBilge Mutlu - Enabling Everyday Use of Robots as Products, Tools, and PlatformsBilge Mutlu - Enabling Everyday Use of Robots as Products, Tools, and PlatformsMuriel Médard - Universal decoding and the grand irrelevance of code constructionMuriel Médard - Universal decoding and the grand irrelevance of code constructionChristoph Studer - Jammer Mitigation in Multi-Antenna SystemsChristoph Studer - Jammer Mitigation in Multi-Antenna SystemsJohan Ugander - Harvesting randomness to understand computational social systemsJohan Ugander - Harvesting randomness to understand computational social systems
Яндекс.Метрика