Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Automated GUI Security Testing: SQL Injection Detection
Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering.
Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering.
2024 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

The growing sophistication of SQL Injection (SQLi) attacks and the limitations of traditional security testing methods present a pressing need for innovative approaches, particularly in GUI-level security testing. Conventional tools often overlook vulnerabilities in user-facing elements such as input fields and login pages, focusing predominantly on backend systems. Automated GUI testing offers a solution by enabling the detection of these vulnerabilities directly at the user interface level. However, many existing tools require extensive technical knowledge or security testing expertise. Our approach leverages automated GUI testing, offering a more user-friendly and effective method for identifying SQLi vulnerabilities within graphical user interfaces (GUIs), specifically in login pages.

This thesis introduces a proof-of-concept plugin developed for the Scout tool, which integrates the plugin into its augmented testing framework. Scout overlays a visual layer between the system under test (SUT) and the tester, facilitating intuitive interaction with the application. The primary goal of the plugin is to automate SQLi detection at the GUI level, combining security testing with Scout’s augmented testing paradigm, hence enabling non-security-trained testers. While augmented testing is established in GUI testing, its combination with security testing—particularly SQLi—has not been extensively studied. This research aims to fill that gap by evaluating the plugin's effectiveness in streamlining SQLi detection and improving the overall security testing process.

The plugin was evaluated through a quasi-experiment, where its effectiveness in identifying SQLi vulnerabilities was measured across three open-source platforms: OWASP Juice Shop, bWAPP, and AltoroJ. A total of 906 test executions, spanning 302 SQLi test cases, were conducted. Results were analyzed using descriptive statistics, including bar graphs and box plots. The findings suggest that the plugin effectively detects SQLi vulnerabilities, particularly in login pages. The perception study further revealed that non-security-expert practitioners perceived the plugin to be useful and effective but recommended enhancements to further expand the plugin's capabilities.

In conclusion, this study demonstrates the potential of combining augmented testing with automated GUI security testing to detect SQLi vulnerabilities. While the plugin shows promise in improving both test effectiveness and usability, a more formal study is required to fully validate its effectiveness in real-world environments. Future work should focus on expanding the plugin's functionality, incorporating more types of SQLi, and validating the approach in real-world environments.

Place, publisher, year, edition, pages
2024. , p. 117
Keywords [en]
Testing, Security Testing, Automated Testing, Automated GUI Testing, SQL Injection
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:bth-27034OAI: oai:DiVA.org:bth-27034DiVA, id: diva2:1908737
Subject / course
PA2534 Master's Thesis (120 credits) in Software Engineering
Educational program
PAADA Master Qualification Plan in Software Engineering 120,0 hp
Presentation
2024-09-23, C245, Blekinge Tekniska Högskola, Valhallavägen 1, 371 41, Blekinge, Karlskrona, 19:00 (English)
Supervisors
Examiners
Available from: 2024-11-07 Created: 2024-10-28 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

fulltext(2992 kB)621 downloads
File information
File name FULLTEXT02.pdfFile size 2992 kBChecksum SHA-512
09db499b09b4d0c0984d579db5ae9c33431bdfa175009bb62e4103d9373de6f18a530b57f9e482c6935befaa323e7b155b3612c45d4a4be80bd8b616279e2d74
Type fulltextMimetype application/pdf

By organisation
Department of Software Engineering
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 623 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 1038 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf