Published May 3, 2022 | Version v1
Dataset Open

Appendix to Combinatorial Methods for Dynamic Gray-Box SQL Injection Testing

  • 1. SBA Research

Description

This appendix contains the detailed results of our case study performed in the context of our article "Combinatorial Methods for Dynamic Gray-Box SQL Injection Testing", published in the Journal of Software Testing, Verification and Reliability.


For each web application investigated, one table exists, provided as a separate PDF file.
In each of these tables, the results are grouped by endpoint. For each investigated approach, we list the total number of submitted vectors, the number of injected vectors and the injection rate, the amount of executed vectors and the execution rate, and the total time required to submit the attack vectors and evaluate the responses.

Please note that no false positive endpoints are listed for WAVSEP. Furthermore, some entries for the execution rate may be displayed as 0.00 despite some vectors having been executed; this is merely a consequence of rounding.

Files

results_dvwa.pdf

Files (876.1 kB)

Name Size Download all
md5:08fd02cb6e5942b6029164da755cbdd9
91.8 kB Preview Download
md5:4900a400bb14f6d4097cdfb0c8fdb45d
91.7 kB Preview Download
md5:1b83bace5da271dafb19d60794e3da03
93.6 kB Preview Download
md5:9dead1f7dd300da66df8496d7446d099
97.4 kB Preview Download
md5:36ac9681bec01610a468f5d0fa6c9ed8
99.8 kB Preview Download
md5:39a283a4772f9c061db9d05ebc8410ba
119.2 kB Preview Download
md5:7274544ae64f72ab70d6337ff906cd3c
95.1 kB Preview Download
md5:c4c0f99880caaa20a7dcb91b031ec95f
93.9 kB Preview Download
md5:4619d6dafac69b825be503046d796633
93.6 kB Preview Download