Fetching the paper…
Reading the bibliography…
Penetration testing is essential to ensure Web security, which can detect and fix vulnerabilities in advance, and prevent data leakage and serious consequences.
A benchmark tutorial
Walter J Price. 1989 · 1989
Earlier work this paper cites.
Testing finite state machines. In Proceedings of the twenty-third annual ACM symposium on Theory of computing . 476–485
Mihalis Yannakakis. 1991 · 1991
Earlier work this paper cites.
Penetration testing
Clark Weissman. 1995 · 1995
Earlier work this paper cites.
Software penetration testing
Brad Arkin, Scott Stender, and Gary McGraw. 2005 · 2005
Earlier work this paper cites.
Automata, computability and complexity: theory and applications
Elaine Rich et al · 2008
Earlier work this paper cites.
Precise interface identification to improve testing and analysis of web applications. In Proceedings of the eighteenth international symposium on Software testing and analysis . 285–296
William GJ Halfond, Saswat Anand, and Alessandro Orso. 2009 · 2009
Earlier work this paper cites.
Inferring mealy machines. In International Symposium on Formal Methods . Springer, 207–222
Muzammil Shahbaz and Roland Groz. 2009 · 2009
Earlier work this paper cites.
Enemy of the State: A State-Aware Black-Box Web Vulnerability Scanner. In 21st USENIX Security Symposium (USENIX Security 12) . USENIX Association, Bellevue, WA, 523–538
Adam Doupé, Ludovico Cavedon, Christopher Kruegel, and Giovanni Vigna. 2012 · 2012
Earlier work this paper cites.
Detecting vulnerabilities in web applications using automated black box and manual penetration testing. In International Conference on Security of Information and Communication Networks . Springer, 230–239
Nor Fatimah Awang and Azizah Abd Manaf. 2013 · 2013
Earlier work this paper cites.
Automated testing for SQL injection vulnerabilities: an input mutation approach. In Proceedings of the 2014 International Symposium on Software Testing and Analysis . 259–269
Dennis Appelt, Cu Duy Nguyen, Lionel C Briand, and Nadia Alshahwan. 2014 · 2014
Earlier work this paper cites.
Docker: lightweight linux containers for consistent development and deployment
Dirk Merkel. 2014 · 2014
Earlier work this paper cites.
An automated method of penetration testing. In 2014 IEEE Computers, Communications and IT Applications Conference . IEEE, 211–216
Xue Qiu, Shuguang Wang, Qiong Jia, Chunhe Xia, and Qingxin Xia. 2014 · 2014
Earlier work this paper cites.
Penetration Testing: A Review
Kumar Shravan, Bansal Neha, and Bhadana Pawan. 2014 · 2014
Earlier work this paper cites.
SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities. In 23rd USENIX Security Symposium (USENIX Security 14) . USENIX Association, San Diego, CA, 495–510
Yuchen Zhou and David Evans. 2014 · 2014
Earlier work this paper cites.
A black-box approach to detect vulnerabilities in web services using penetration testing
Marcelo Invert Palma Salas and Eliane Martins. 2015 · 2015
Earlier work this paper cites.
How to build a benchmark. In Proceedings of the 6th ACM/SPEC international conference on performance engineering . 333–336
Jóakim v. Kistowski, Jeremy A Arnold, Karl Huppler, Klaus-Dieter Lange, John L Henning, and Paul Cao. 2015 · 2015
Earlier work this paper cites.
Penetration testing automation assessment method based on rule tree. In 2015 IEEE International Conference on Cyber Technology in Automation, Control, and Intelligent Systems (CYBER) . IEEE, 1829–1833
Jianming Zhao, Wenli Shang, Ming Wan, and Peng Zeng. 2015 · 2015
Earlier work this paper cites.
Automated and effective testing of web services for XML injection attacks. In Proceedings of the 25th International Symposium on Software Testing and Analysis . 12–23
Sadeeq Jan, Cu D Nguyen, and Lionel C Briand. 2016 · 2016
Earlier work this paper cites.
Analysis and exercises for engaging beginners in online { \{ CTF } \} competitions for security education. In 2017 USENIX Workshop on Advances in Security Education (ASE 17)
Tanner J Burns, Samuel C Rios, Thomas K Jordan, Qijun Gu, and Trevor Underwood. 2017 · 2017
Earlier work this paper cites.
How the Web Tangled Itself: Uncovering the History of { \{ Client-Side } \} Web ( { \{ In) Security } \} . In 26th USENIX Security Symposium (USENIX Security 17) . 971–987
Ben Stock, Martin Johns, Marius Steffens, and Michael Backes. 2017 · 2017
Cited alongside, same era.
Attention is all you need
A Vaswani. 2017 · 2017
Cited alongside, same era.
Automated penetration testing: An overview. In The 4th international conference on natural language computing, Copenhagen, Denmark . 121–129
Farah Abu-Dabaseh and Esraa Alshammari. 2018 · 2018
Cited alongside, same era.
King of the Hill: A Novel Cybersecurity Competition for Teaching Penetration Testing. In 2018 USENIX Workshop on Advances in Security Education (ASE 18) . USENIX Association, Baltimore, MD
Kevin Bock, George Hughey, and Dave Levin. 2018 · 2018
Cited alongside, same era.
Automated penetration testing using deep reinforcement learning. In 2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) . IEEE, 2–10
Meta AI Blog: Meta LLaMA 3.1
Meta AI. 2024 · 2024
Closest in time.
Introducing Claude 3.5 Sonnet
Anthropic. 2024 · 2024
Closest in time.
LangChain
Harrison Chase. 2022 · 2024
Closest in time.
Abhimanyu Dubey, Abhinav Jauhri, Abhinav Pandey, Abhishek Kadian, Ahmad Al-Dahle, Aiesha Letman, Akhil Mathur, Alan Schelten, Amy Yang, Angela Fan, et al · 2024
Closest in time.
OpenAI et al. 2024 · 2024
Closest in time.
Large Language Models Can Connect the Dots: Exploring Model Optimization Bugs with Domain Knowledge-Aware Prompts. In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis . 1579–1591
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Zhenguo Hu, Razvan Beuran, and Yasuo Tan. 2020 · 2020
Cited alongside, same era.
Learning Moore machines from input–output traces
Georgios Giantamidis, Stavros Tripakis, and Stylianos Basagiannis. 2021 · 2021
Cited alongside, same era.
A deep learning-based penetration testing framework for vulnerability identification in internet of things environments. In 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) . IEEE, 887–894
Nickolaos Koroniotis, Nour Moustafa, Benjamin Turnbull, Francesco Schiliro, Praveen Gauravaram, and Helge Janicke. 2021 · 2021
Cited alongside, same era.
Penetration Testing Sistem Jaringan Komputer Menggunakan Kali Linux untuk Mengetahui Kerentanan Keamanan Server dengan Metode Black Box: Studi Kasus Web Server Diva Karaoke. co. id
Marzuki Hasibuan and Andi Marwan Elhanafi. 2022 · 2022
Cited alongside, same era.
HackTheBox
2023 · 2023
Cited alongside, same era.
Hallucination detection: Robustly discerning reliable answers in large language models. In Proceedings of the 32nd ACM International Conference on Information and Knowledge Management . 245–255
Yuyan Chen, Qiang Fu, Yichen Yuan, Zhihao Wen, Ge Fan, Dayiheng Liu, Dongmei Zhang, Zhixu Li, and Yanghua Xiao. 2023 · 2023
Cited alongside, same era.
Information Supplement: Penetration Testing Guidance
PCI Security Standards Council. 2017 · 2023
Cited alongside, same era.
{ \{ ACTOR } \} : { \{ Action-Guided } \} Kernel Fuzzing. In 32nd USENIX Security Symposium (USENIX Security 23) . 5003–5020
Marius Fleischer, Dipanjan Das, Priyanka Bose, Weiheng Bai, Kangjie Lu, Mathias Payer, Christopher Kruegel, and Giovanni Vigna. 2023 · 2023
Cited alongside, same era.
Hao Guan, Guangdong Bai, and Yepang Liu. 2024 · 2024
Closest in time.
Atropos: Effective fuzzing of web applications for server-side vulnerabilities. In USENIX Security Symposium
Emre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars, Philipp Görz, Xinyi Xu, Cemal Kaygusuz, and Thorsten Holz. 2024 · 2024
Closest in time.
LLMs as Hackers: Autonomous Linux Privilege Escalation Attacks
Andreas Happe, Aaron Kaplan, and Juergen Cito. 2024 · 2024
Closest in time.
Haibo Jin, Ruoxi Chen, Andy Zhou, Jinyin Chen, Yang Zhang, and Haohan Wang. 2024 · 2024
Closest in time.
Personal llm agents: Insights and survey about the capability, efficiency and security
Yuanchun Li, Hao Wen, Weijun Wang, Xiangyu Li, Yizhen Yuan, Guohong Liu, Jiacheng Liu, Wenxing Xu, Xiang Wang, Yi Sun, et al · 2024
Closest in time.
Large language models: A survey
Shervin Minaee, Tomas Mikolov, Narjes Nikzad, Meysam Chenaghlu, Richard Socher, Xavier Amatriain, and Jianfeng Gao. 2024 · 2024
Closest in time.
{ \{ SoK } \} : All You Need to Know About { \{ On-Device } \} { \{ ML } \} Model Extraction-The Gap Between Research and Practice. In 33rd USENIX Security Symposium (USENIX Security 24) . 5233–5250
Tushar Nayan, Qiming Guo, Mohammed Al Duniawi, Marcus Botacin, Selcuk Uluagac, and Ruimin Sun. 2024 · 2024
Closest in time.
Common Vulnerability Scoring System SIG
Forum of Incident Response and Security Teams. 2024 · 2024
Closest in time.
NYU CTF Dataset: A Scalable Open-Source Benchmark Dataset for Evaluating LLMs in Offensive Security
Minghao Shao, Sofija Jancheska, Meet Udeshi, Brendan Dolan-Gavitt, Haoran Xi, Kimberly Milner, Boyuan Chen, Max Yin, Siddharth Garg, Prashanth Krishnamurthy, Farshad Khorrami, Ramesh Karri, and Muhammad Shafique. 2024 · 2024
Closest in time.
OWASP Top 10
The OWASP Top 10 2021 team. [n. d.] · 2024
Closest in time.
webAI: Enterprise Grade Local AI Applications
webAI. 2024 · 2024
Closest in time.
SCALE: Constructing Structured Natural Language Comment Trees for Software Vulnerability Detection. In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis . 235–247
Xin-Cheng Wen, Cuiyun Gao, Shuzheng Gao, Yang Xiao, and Michael R Lyu. 2024 · 2024
Closest in time.
Llm inference unveiled: Survey and roofline model insights
Zhihang Yuan, Yuzhang Shang, Yang Zhou, Zhen Dong, Chenhao Xue, Bingzhe Wu, Zhikai Li, Qingyi Gu, Yong Jae Lee, Yan Yan, et al · 2024
Closest in time.
How Effective Are They? Exploring Large Language Model Based Fuzz Driver Generation. In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis . 1223–1235
Cen Zhang, Yaowen Zheng, Mingqiang Bai, Yeting Li, Wei Ma, Xiaofei Xie, Yuekang Li, Limin Sun, and Yang Liu. 2024 · 2024
Closest in time.