Model-driven Security Testing of SAML Single Sign-On System
Weitao Hou, Menghao Li, Jian Liu, Wei Huo · 2018
According to investigation, existing works of security testing for Single Sign-on systems (SSO) on the Security Assertion Markup Language (SAML) are based on partially automatic code review methods, which lead to a low level in effectiveness and reusability.In response to these limitations, a new automatic model-driven security testing framework is proposed.This method utilizes a broker-agent to obtain input traces automatically.Different from most previous methods which are applied to OAuth or openID protocols, in our method a customized fuzzy testing engine is designed to SAML protocol.This engine includes special mutation strategies and an abnormal monitor mechanism.Based on this approach, we have developed a prototypical tool called SSOFuzzer and evaluated it with several SSO reference systems, such as onelogin and myOneLogin.The experimental results show that compared to semi-automatic tools like SAMLRaider, SSOFuzzer can accelerate the generation of test cases by 12.4 times.SSOFuzzer also found four unknown security flaws and one known security flaw from our benchmark systems.