Testrex: A testbed for repeatable exploits

S. Dashevskyi, F. Massacci, D.R. dos Santos, A. Sabetta

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

Abstract

© 2014 USENIX Association. All rights reserved.Web applications are the target of many known exploits and also a fertile ground for the discovery of security vulnerabilities. Those applications may be exploitable not only because of the vulnerabilities in their source code, but also because of the environments on which they are deployed and run. Execution environments usually consist of application servers, databases and other supporting applications. In order to test whether known exploits can be reproduced in different settings, better understand their effects and facilitate the discovery of new vulnerabilities, we need to have a reliable testbed. In this paper, we present TESTREX, a testbed for repeatable exploits, which has as main features: packing and running applications with their environments; injecting exploits and monitoring their success; and generating security reports. We also provide a corpus of example applications, taken from related works or implemented by us.
Original languageEnglish
Title of host publication7th Workshop on Cyber Security Experimentation and Test, CSET 2014
PublisherUSENIX Association
Publication statusPublished - 2014
Externally publishedYes
Event7th Workshop on Cyber Security Experimentation and Test, CSET 2014 - San Diego, United States
Duration: 18 Aug 2014 → …

Publication series

Name7th Workshop on Cyber Security Experimentation and Test, CSET 2014

Conference

Conference7th Workshop on Cyber Security Experimentation and Test, CSET 2014
Country/TerritoryUnited States
CitySan Diego
Period18/08/14 → …

Fingerprint

Dive into the research topics of 'Testrex: A testbed for repeatable exploits'. Together they form a unique fingerprint.

Cite this