TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yang, Guan-Yan, Wang, Farn, Gu, You-Zong, Teng, Ya-Wen, Yeh, Kuo-Hui, Ho, Ping-Hsueh, Wen, Wei-Ling
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918140556869632
author Yang, Guan-Yan
Wang, Farn
Gu, You-Zong
Teng, Ya-Wen
Yeh, Kuo-Hui
Ho, Ping-Hsueh
Wen, Wei-Ling
author_facet Yang, Guan-Yan
Wang, Farn
Gu, You-Zong
Teng, Ya-Wen
Yeh, Kuo-Hui
Ho, Ping-Hsueh
Wen, Wei-Ling
contents The rapid proliferation of network applications has led to a significant increase in network attacks. According to the OWASP Top 10 Projects report released in 2021, injection attacks rank among the top three vulnerabilities in software projects. This growing threat landscape has increased the complexity and workload of software testing, necessitating advanced tools to support agile development cycles. This paper introduces a novel test prioritization method for SQL injection vulnerabilities to enhance testing efficiency. By leveraging previous test outcomes, our method adjusts defense strength vectors for subsequent tests, optimizing the testing workflow and tailoring defense mechanisms to specific software needs. This approach aims to improve the effectiveness and efficiency of vulnerability detection and mitigation through a flexible framework that incorporates dynamic adjustments and considers the temporal aspects of vulnerability exposure.
format Preprint
id arxiv_https___arxiv_org_abs_2509_10920
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
Yang, Guan-Yan
Wang, Farn
Gu, You-Zong
Teng, Ya-Wen
Yeh, Kuo-Hui
Ho, Ping-Hsueh
Wen, Wei-Ling
Software Engineering
Cryptography and Security
The rapid proliferation of network applications has led to a significant increase in network attacks. According to the OWASP Top 10 Projects report released in 2021, injection attacks rank among the top three vulnerabilities in software projects. This growing threat landscape has increased the complexity and workload of software testing, necessitating advanced tools to support agile development cycles. This paper introduces a novel test prioritization method for SQL injection vulnerabilities to enhance testing efficiency. By leveraging previous test outcomes, our method adjusts defense strength vectors for subsequent tests, optimizing the testing workflow and tailoring defense mechanisms to specific software needs. This approach aims to improve the effectiveness and efficiency of vulnerability detection and mitigation through a flexible framework that incorporates dynamic adjustments and considers the temporal aspects of vulnerability exposure.
title TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
topic Software Engineering
Cryptography and Security
url https://arxiv.org/abs/2509.10920