Project Ava: On the Matter of Using Machine Learning for Web Application Security Testing – Part 8: Development of Prototype #4 – Building on Takaesu’s Approach with Focus on XSS
ID: f879cf96-2080-533e-aaa5-cb46803675fd
STIX ID: report--f879cf96-2080-533e-aaa5-cb46803675fd
Feed Name: NCC Research
NCC Group's Project Ava blog describes revisiting Isao Takaesu’s XSS discovery approaches by building PoC ML solutions: an LSTM-RNN to generate XSS payload segments coupled with a massively multi-threaded genetic algorithm for mutation and selection. The team details input-dictionary strategies, evaluation criteria for payloads, use of a dockerised Selenium hub to enable parallel testing, infrastructure and memory challenges, and tuning steps (guided learning, selective Selenium testing) that reduced runtime and improved results; the model is promising but still preliminary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
