Large-scale Security Analysis of HTTP Responses

dc.contributor.authorCarbol, Jonathan
dc.contributor.authorStegrell, Hugo
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerSabelfeld, Andrei
dc.contributor.supervisorEriksson, Benjamin
dc.date.accessioned2023-12-22T10:07:24Z
dc.date.available2023-12-22T10:07:24Z
dc.date.issued2023
dc.date.submitted2023
dc.description.abstractEnsuring the security of computer systems has never been more critical as our reliability on software is ever-increasing. It is not enough to create systems that work securely during their development. Instead, systems and software need continuous development and updates to stay secure. Inspecting individual web applications for security vulnerabilities and concerns gives a lot of feedback for the specific web applications being checked. However, the impact of particular vulnerabilities can be more accurately observed by looking for vulnerabilities in a larger sample size of web applications. In order to find vulnerabilities on a large scale, this thesis utilizes the crawl data from Common Crawl, an open repository of web crawl data. In this data, indicators of specific programs, software, or libraries are visible, allowing us to find vulnerable versions. Utilizing cloud computing on AWS and the crawl data, this thesis showcases how to scan 3 billion websites to find indicators of vulnerabilities on millions of domains. Using dynamic verification of the results, thousands of these indicators of vulnerabilities are then shown to be verifiable.
dc.identifier.coursecodeDATX05
dc.identifier.urihttp://hdl.handle.net/20.500.12380/307476
dc.language.isoeng
dc.setspec.uppsokTechnology
dc.subjectSecurity
dc.subjectcyber security
dc.subjectvulnerabilities
dc.subjectcommon crawl
dc.subjectAWS
dc.subjectcloud computing
dc.subjectcomputer science
dc.subjectengineering
dc.titleLarge-scale Security Analysis of HTTP Responses
dc.type.degreeExamensarbete för masterexamensv
dc.type.degreeMaster's Thesisen
dc.type.uppsokH
local.programmeComputer systems and networks (MPCSN), MSc
local.programmeComputer science – algorithms, languages and logic (MPALG), MSc

Ladda ner

Original bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 23-90 JC HS.pdf
Storlek:
3.84 MB
Format:
Adobe Portable Document Format

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Storlek:
2.35 KB
Format:
Item-specific license agreed upon to submission
Beskrivning: