Model-driven Security Testing of SAML Single Sign-On System

Weitao Hou, Menghao Li, Jian Liu, Wei Huo · 2018

According to investigation, existing works of security testing for Single Sign-on systems (SSO) on the Security Assertion Markup Language (SAML) are based on partially automatic code review methods, which lead to a low level in effectiveness and reusability.In response to these limitations, a new automatic model-driven security testing framework is proposed.This method utilizes a broker-agent to obtain input traces automatically.Different from most previous methods which are applied to OAuth or openID protocols, in our method a customized fuzzy testing engine is designed to SAML protocol.This engine includes special mutation strategies and an abnormal monitor mechanism.Based on this approach, we have developed a prototypical tool called SSOFuzzer and evaluated it with several SSO reference systems, such as onelogin and myOneLogin.The experimental results show that compared to semi-automatic tools like SAMLRaider, SSOFuzzer can accelerate the generation of test cases by 12.4 times.SSOFuzzer also found four unknown security flaws and one known security flaw from our benchmark systems.

Read the paper · More papers on PaperTik