Automating XSS Vulnerability Testing Using Reinforcement Learning

Kento Hasegawa, Seira Hidano, Kazuhide Fukushima

2023

Abstract

Cross-site scripting (XSS) is a frequently exploited vulnerability in web applications. Existing XSS testing tools utilize a brute-force or heuristic approach to discover vulnerabilities, which increases the testing time and load of the target system. Reinforcement learning (RL) is expected to decrease the burden on humans and enhance the efficiency of the testing task. This paper proposes a method to automate XSS vulnerability testing using RL. RL is employed to obtain an efficient policy to compose test strings for XSS vulnerabilities. Based on an observed state, an agent composes a test string that exploits an XSS vulnerability and passes the string to a target web page. A training environment XSS Gym is developed to provide a variety of XSS vulnerabilities during training. The proposed method significantly decreases the number of requests to the target web page during the testing process by acquiring an efficient policy with RL. Experimental results demonstrate that the proposed method effectively discovers XSS vulnerabilities with the fewest requests compared to the existing open-source tools.

Download


Paper Citation


in Harvard Style

Hasegawa K., Hidano S. and Fukushima K. (2023). Automating XSS Vulnerability Testing Using Reinforcement Learning. In Proceedings of the 9th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP, ISBN 978-989-758-624-8, pages 70-80. DOI: 10.5220/0011653600003405


in Bibtex Style

@conference{icissp23,
author={Kento Hasegawa and Seira Hidano and Kazuhide Fukushima},
title={Automating XSS Vulnerability Testing Using Reinforcement Learning},
booktitle={Proceedings of the 9th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,},
year={2023},
pages={70-80},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0011653600003405},
isbn={978-989-758-624-8},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 9th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,
TI - Automating XSS Vulnerability Testing Using Reinforcement Learning
SN - 978-989-758-624-8
AU - Hasegawa K.
AU - Hidano S.
AU - Fukushima K.
PY - 2023
SP - 70
EP - 80
DO - 10.5220/0011653600003405