Large-scale Security Analysis of HTTP Responses
dc.contributor.author | Carbol, Jonathan | |
dc.contributor.author | Stegrell, Hugo | |
dc.contributor.department | Chalmers tekniska högskola / Institutionen för data och informationsteknik | sv |
dc.contributor.department | Chalmers University of Technology / Department of Computer Science and Engineering | en |
dc.contributor.examiner | Sabelfeld, Andrei | |
dc.contributor.supervisor | Eriksson, Benjamin | |
dc.date.accessioned | 2023-12-22T10:07:24Z | |
dc.date.available | 2023-12-22T10:07:24Z | |
dc.date.issued | 2023 | |
dc.date.submitted | 2023 | |
dc.description.abstract | Ensuring the security of computer systems has never been more critical as our reliability on software is ever-increasing. It is not enough to create systems that work securely during their development. Instead, systems and software need continuous development and updates to stay secure. Inspecting individual web applications for security vulnerabilities and concerns gives a lot of feedback for the specific web applications being checked. However, the impact of particular vulnerabilities can be more accurately observed by looking for vulnerabilities in a larger sample size of web applications. In order to find vulnerabilities on a large scale, this thesis utilizes the crawl data from Common Crawl, an open repository of web crawl data. In this data, indicators of specific programs, software, or libraries are visible, allowing us to find vulnerable versions. Utilizing cloud computing on AWS and the crawl data, this thesis showcases how to scan 3 billion websites to find indicators of vulnerabilities on millions of domains. Using dynamic verification of the results, thousands of these indicators of vulnerabilities are then shown to be verifiable. | |
dc.identifier.coursecode | DATX05 | |
dc.identifier.uri | http://hdl.handle.net/20.500.12380/307476 | |
dc.language.iso | eng | |
dc.setspec.uppsok | Technology | |
dc.subject | Security | |
dc.subject | cyber security | |
dc.subject | vulnerabilities | |
dc.subject | common crawl | |
dc.subject | AWS | |
dc.subject | cloud computing | |
dc.subject | computer science | |
dc.subject | engineering | |
dc.title | Large-scale Security Analysis of HTTP Responses | |
dc.type.degree | Examensarbete för masterexamen | sv |
dc.type.degree | Master's Thesis | en |
dc.type.uppsok | H | |
local.programme | Computer systems and networks (MPCSN), MSc | |
local.programme | Computer science – algorithms, languages and logic (MPALG), MSc |