Slide 27
Slide 27 text
27
Three issues are not adequately resolved
Existing test tools and manual verification
[1] Zhou, Yuchen, and David Evans. "SSOScan: Automated testing of web applications for Single Sign-On
vulnerabilities." 23rd {USENIX} Security Symposium ({USENIX} Security 14). 2014.
[2] Mainka, Christian, et al. "SoK: single sign-on security—an evaluation of openID connect." 2017 IEEE European
Symposium on Security and Privacy (EuroS&P). IEEE, 2017.
Tool Test Coverage
Customizability of
scenarios
Reproducibility
SSOScan[1]
△
Only spec-based
vulns (5)
△
Requirement 1
◯
Automation
PrOfESSOS[2]
△
Only spec-based
vulns (11)
△
Requirement 1,2
◯
Automation
Manual
Testing
◯
Spec-based vulns,
impl-based vulns
◯
Requirement 1,2,3,4
△
Manual