Uppsats

Artificial Intelligence Driven Analysis of Web Applications Using Interaction Data in a Black-Box Framework

Kandidat-uppsats

KTH/Skolan för elektroteknik och datavetenskap (EECS)

Publicerad: 2025

Språk: Engelska

Sammanfattning

Web applications have become central to how modern services are delivered, but their growing complexity poses significant challenges to ensuring security. Traditional techniques for vulnerability detection—such as static analysis, dynamic testing, and manual code reviews—often require access to source code, suffer from scalability issues, or generate high rates of false positives and false negatives. These limitations are particularly pronounced in black-box scenarios, where internal application logic is not accessible. To address these challenges, researchers have proposed a variety of novel approaches that leverage advances in machine learning, natural language processing, and other areas of artificial intelligence. These techniques hold promise for automating and improving the accuracy of vulnerability detection, even in complex and opaque web applications. This thesis presents an AI-driven framework designed to detect security vulnerabilities in web applications using only interaction data collected through black-box testing. By observing how users interact with an application and analyzing the behavior of its client-side components, the system builds a predictive model capable of identifying potentially vulnerable code. The framework leverages an ensemble of machine learning models, combining insights from both sequential patterns and structural relationships within the application. To support this, we curated and preprocessed a large dataset of JavaScript code and applied controlled obfuscation to simulate real-world conditions. Our approach was developed and evaluated in collaboration with cybersecurity firm Outpost24, allowing for real-world validation. The results show that the proposed method improves vulnerability detection accuracy and provides more actionable feedback for developers compared to traditional approaches. Ultimately, this work demonstrates the feasibility and value of combining artificial intelligence with black-box analysis to address modern web security challenges, and offers a pathway toward more scalable, adaptable, and automated solutions in the cybersecurity domain.

Information

Lärosäte / institution
KTH/Skolan för elektroteknik och datavetenskap (EECS)
Publiceringsdatum
2025
Uppsatstyp
Kandidat-uppsats
Språk
Engelska