Zokfuzz: Detection of Web Vulnerabilities via Fuzzing

Hao Zhang, Weiyu Dong, Liehui Jiang · 2022 2nd International Conference on Consumer Electronics and Computer Engineering (ICCECE) · 2022

Fuzzing is one of the mainstream web application automated vulnerability detection methods. Because of its black box characteristics, it can be used to detect vulnerabilities without knowing the source code of the target application, so it is widely used. However, traditional web application fuzzing methods have the disadvantages of limited test cases, slow execution process, and low efficiency. In order to solve these problems, some scholars introduced genetic algorithms in the fuzzing process. However, after the test cases are entered, it is difficult to automatically detect the state of the web application, which will lead to deviations in the evolution direction of the population and the high aggressiveness of the test cases. This paper proposes a web application fuzzing script, which can realize automatic monitoring of web application status changes, and at the same time more accurately judge whether the test case is offensive. On this basis, an improved mutation method is proposed to enable the population to quickly evolve more aggressive test cases. Experimental results show that ZokFuzz can detect more web vulnerabilities compared to X-Ray and Burp Suite.

Read the paper · More papers on PaperTik