A formal and automated approach to exploiting multi-stage attacks of web applications

Federico De Meo, Luca Viganò · Journal of Computer Security · 2020

We propose a formal and automated approach that allows one to (i) reason about vulnerabilities of web applications and (ii) combine multiple vulnerabilities for the identification of complex, multi-stage attacks. We have developed WAFEx, an automatic tool that implements our approach and we show its efficiency by applying it to real-world case studies. WAFEx was able to generate, and exploit, previously unknown attacks.

Read the paper · More papers on PaperTik