CSRF Detection Based on Graph Data Mining

Chang Liu, Xuan Shen, Min Gao, Wei Dai · 2020

CSRF is a popular web security vulnerability. To detect this type of vulnerability, we need to analyze the relationship between HTTP request parameters and state transitions on the server side. However, the existing detection methods are not suitable for detecting this vulnerability. In this paper, we propose a method to detect CSRF by capturing the execution traces of web application and importing them into graph database. Then we use data mining to find HTTP requests that could cause the state transitions on the server side, and infer the type of all the parameters contained in the request parameter, so as to detect the CSRF vulnerability. Experiments show that this method is feasible.

Read the paper · More papers on PaperTik