SpiderSapien: Client-Centric Web Crawler and Security Scanner
New arXiv paper proposes a client-centric crawler that renders JavaScript in-browser to improve black-box web-app scanning — relevant for teams whose DAST tools struggle with SPA-heavy targets.
Summary written by editorial AI · Source link below
arXiv:2609.02532v1 Announce Type: new Abstract: Black-box web application crawling and scanning play an important role for security testing of web applications. Yet state-of-the-art scanners fall short of addressing key characteristics of a modern web application: its extreme dynamism and interactivity on the client side. This paper identifies immersive interaction as a key ingredient for scanners to deeply explore modern web applications. We propose SpiderSapien, a client-centric crawler and s
Editorial Analysis
Modern web apps built as SPAs often evade traditional scanners; a client-rendering approach could close DAST coverage gaps in AppSec programs.
Benchmark your current DAST tools against JavaScript-heavy apps and track emerging crawlers like SpiderSapien for potential integration.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the Research Desk
- 39 New Methods That Compromise Passkey Authentication3d
- Security Vulnerability in a Voting System3d
- Selfie-Capture Dynamics as an Auxiliary Signal Against Deepfakes and Injection Attacks for Mobile Identity Verification4d
- How Reliable Is the Multi-Input Heuristic for Bitcoin Address Clustering in Law Enforcement Contexts?4d
- Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks4d