Automated Multi-Step Web Application Attack Analysis Using Reinforcement Learning and Vulnerability Assessment Tools

Mohammad Sedigh Hamidi, Mohammad-Ali Doostari, Shahriar Bijani · Research Square · 2023

Abstract Web applications remain persistently vulnerable to malicious attacks, necessitating a thorough exploration of adversarial strategies in multi-step web application attacks to proactively enhance preventive measures. Nonetheless, the complexity of such audits demands specialized expertise, and notably, the automation of this complicated process lacks practical methodologies. This paper presents an innovative approach that automates multi-step web application attacks by integrating reinforcement learning techniques with established tools like Metasploit, SQLmap, and Weevely. Within this framework, reinforcement learning agents exploit SQL injection and known vulnerabilities outlined in the OWASP Top Ten. A comparative analysis of two reinforcement learning models, Q-Learning and Deep Q-Network, reveals the superior reward accumulation prowess of the Q-Learning model during the training phase. Furthermore, the effectiveness of these trained agents is assessed using the vulnerable DVWA web application, demonstrating the Q-Learning-trained agent could gain persistent access to the web server and successfully extracting sensitive data.

Read the paper · More papers on PaperTik