An early testing and defense web application framework for malicious input attacks
Michael Gegick, Eric Isakson, Laurie A. Williams · NCSU Libraries Repository (North Carolina State University Libraries) · 2006
Input validation vulnerabilities, one of the largest problems in software security today, are readily identified by software assurance (SA) tools.Software development organizations are increasingly adopting SA tools to quickly identify vulnerabilities in their software systems.These tools, usually applied when implementation is complete, have a comprehensive and extendable rule set to detect known and new vulnerabilities.A simple and effective framework is needed to provide developers with a strategic approach to securing against malicious input attacks early in software development.We introduce a Java Web Application Reliability and Defense (WARD) framework, a two-part security solution composed of a vulnerability detection component, SecureUnit, and a vulnerability protection component, SecureFilter.SecureUnit enables developers to write automated, reusable, and customizable JUnit penetration tests that launch attacks on their systems to reveal security vulnerabilities.SecureFilter is a customizable server-side choke point containing a regular expression-based filter to match legal input according to system requirements.WARD provides an attack-then-defend approach for developers to build security into a software system early in the software process.We integrated WARD v1.0 with WebGoat, an open-source web application security test bed, and successfully "warded off" 38 of 43 (88%) injected cross-site scripting exploits.WARD v2.0 will address the encoded (e.g. with HTML entities, hex characters) exploits that were not stopped from entering WebGoat in WARD v1.0.