Micro-Id-Gym: a Flexible Tool for Pentesting Identity Management Protocols in the Wild and in the Laboratory
Description
Identity Management (IdM) protocols such as OAuth 2.0, OpenID Connect (OIDC), and SAML 2.0 are critical components of digital infrastructures used by enterprises and public administrations. Ensuring their secure deployment and correct usage is essential to establishing trust in modern digital ecosystems, yet performing systematic security assessments remains challenging. To support researchers and security professionals, we present Micro-Id-Gym, a flexible and automated testing framework designed to create reproducible sandboxes for IdM protocol deployments and to perform penetration testing both in the wild and in controlled laboratory environments.
Micro-Id-Gym enables the reproduction of known exploits, facilitates the discovery of new vulnerabilities, and improves protocol comprehension by providing a reliable, container-based infrastructure for testing authentication and authorization flows. The tool abstracts two key capabilities: the automated creation of IdM sandboxes and the execution of protocol-level pentesting activities. This work demonstrates how Micro-Id-Gym can be used to support security research, experimental analysis, and hands-on training for OAuth, OIDC, and SAML systems.
Files
2020-1.pdf
Files
(536.4 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:66c6164f30a69207b59be44286f3f310
|
536.4 kB | Preview Download |