Automating XSS Vulnerability Testing Using Reinforcement Learning
Kento Hasegawa, Seira Hidano, Kazuhide Fukushima
2023
Abstract
Cross-site scripting (XSS) is a frequently exploited vulnerability in web applications. Existing XSS testing tools utilize a brute-force or heuristic approach to discover vulnerabilities, which increases the testing time and load of the target system. Reinforcement learning (RL) is expected to decrease the burden on humans and enhance the efficiency of the testing task. This paper proposes a method to automate XSS vulnerability testing using RL. RL is employed to obtain an efficient policy to compose test strings for XSS vulnerabilities. Based on an observed state, an agent composes a test string that exploits an XSS vulnerability and passes the string to a target web page. A training environment XSS Gym is developed to provide a variety of XSS vulnerabilities during training. The proposed method significantly decreases the number of requests to the target web page during the testing process by acquiring an efficient policy with RL. Experimental results demonstrate that the proposed method effectively discovers XSS vulnerabilities with the fewest requests compared to the existing open-source tools.
DownloadPaper Citation
in Harvard Style
Hasegawa K., Hidano S. and Fukushima K. (2023). Automating XSS Vulnerability Testing Using Reinforcement Learning. In Proceedings of the 9th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP, ISBN 978-989-758-624-8, pages 70-80. DOI: 10.5220/0011653600003405
in Bibtex Style
@conference{icissp23,
author={Kento Hasegawa and Seira Hidano and Kazuhide Fukushima},
title={Automating XSS Vulnerability Testing Using Reinforcement Learning},
booktitle={Proceedings of the 9th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,},
year={2023},
pages={70-80},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0011653600003405},
isbn={978-989-758-624-8},
}
in EndNote Style
TY - CONF
JO - Proceedings of the 9th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,
TI - Automating XSS Vulnerability Testing Using Reinforcement Learning
SN - 978-989-758-624-8
AU - Hasegawa K.
AU - Hidano S.
AU - Fukushima K.
PY - 2023
SP - 70
EP - 80
DO - 10.5220/0011653600003405