NORMA eResearch @NCI Library

Context Aware & Session-Integrated Directed Fuzzing for SQL Injection Detection in Modern Web Applications

Matlaparthi, Kesava Naga Siva Sai (2025) Context Aware & Session-Integrated Directed Fuzzing for SQL Injection Detection in Modern Web Applications. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (1MB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (1MB) | Preview

Abstract

SQL injection (SQLi) remains a serious threat to modern web applications, particularly when vulnerabilities are reachable only after authentication and hidden behind complex session state. Existing tools either rely on heavyweight program analysis and instrumentation, or on large generic payload dictionaries that generate substantial traffic and noise. This thesis investigates whether a deliberately lightweight, aware of the context directed fuzzing approach, integrated with session and token handling and a minimal feedback loop, can efficiently detect SQLi in such settings. The proposed fuzzer automatically logs in, preserves authenticated sessions, and targets only the 1–3 parameters per endpoint that are most likely to reach database queries. It exercises a compact staged set of boolean, error-based and time-based payloads and uses simple content, error and timing oracles to stop as soon as a strong, repeatable signal is observed. The prototype is evaluated on two authenticated lab targets running in Docker: the SQL injection module of Damn Vulnerable Web Application (DVWA) and an authenticated search end- point in OWASP Juice Shop. On DVWA, the fuzzer reliably confirms true SQLi with essentially a single request, achieving millisecond-level Time-to-First-Finding (TTFF) and Requests-per-Finding (RPF) close to 1. On Juice Shop, it maintains valid authentication and quickly surfaces strong oracle-level anomalies on likely database-touching parameters, again with low TTFF and RPF, although these do not correspond to confirmed SQLi. The results show that a modest amount of context awareness and feedback is sufficient to obtain fast, informative signals.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Mahajan, Kamil
UNSPECIFIED
Uncontrolled Keywords: SQL injection; web application security; directed fuzzing; authenticated fuzzing; session management; grey-box testing
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 03 Sep 2026 11:37
Last Modified: 03 Sep 2026 11:37
URI: https://norma.ncirl.ie/id/eprint/9806

Actions (login required)

View Item View Item