메뉴 건너뛰기




Volumn 34, Issue 1, 2008, Pages 65-81

WASP: Protecting web applications using positive tainting and syntax-aware evaluation

Author keywords

Dynamic tainting; Runtime monitoring; Security; SQL injection

Indexed keywords

COMPUTER PROGRAMMING LANGUAGES; DATABASE SYSTEMS; INTERNET; SECURITY OF DATA; SYNTACTICS;

EID: 40449091840     PISSN: 00985589     EISSN: None     Source Type: Journal    
DOI: 10.1109/TSE.2007.70748     Document Type: Article
Times cited : (140)

References (31)
  • 1
    • 0038304275 scopus 로고    scopus 로고
    • Advanced SQL Injection In SQL Server Applications
    • white paper, Next Generation Security Software
    • C. Anley, "Advanced SQL Injection In SQL Server Applications," white paper, Next Generation Security Software, 2002.
    • (2002)
    • Anley, C.1
  • 5
    • 31344435513 scopus 로고    scopus 로고
    • Safe Query Objects: Statically Typed Objects as Remotely Executable Queries
    • May
    • W.R. Cook and S. Rai, "Safe Query Objects: Statically Typed Objects as Remotely Executable Queries," Proc. 27th Int'l Conf. Software Eng. pp. 97-106, May 2005.
    • (2005) Proc. 27th Int'l Conf. Software Eng , pp. 97-106
    • Cook, W.R.1    Rai, S.2
  • 7
    • 4544287108 scopus 로고    scopus 로고
    • Proc. 26th Int'l Conf. Software Eng
    • formal demos, pp, May
    • C. Gould, Z. Su, and P. Devanbu, "JDBC Checker: A Static Analysis Tool for SQL/JDBC Applications," Proc. 26th Int'l Conf. Software Eng., formal demos, pp. 697-698, May 2004.
    • (2004) , pp. 697-698
    • Gould, C.1    Su, Z.2    Devanbu, P.3
  • 8
    • 4544280668 scopus 로고    scopus 로고
    • Static Checking of Dynamically Generated Queries in Database Applications
    • May
    • C. Gould, Z. Su, and P. Devanbu, "Static Checking of Dynamically Generated Queries in Database Applications," Proc. 26th Int'l Conf. Software Eng., pp. 645-654, May 2004.
    • (2004) Proc. 26th Int'l Conf. Software Eng , pp. 645-654
    • Gould, C.1    Su, Z.2    Devanbu, P.3
  • 10
  • 14
    • 84880450431 scopus 로고    scopus 로고
    • Web Application Security Assessment by Fault Injection and Behavior Monitoring
    • May
    • Y. Huang, S. Huang, T. Lin, and C. Tsai, "Web Application Security Assessment by Fault Injection and Behavior Monitoring," Proc. 12th Int'l Conf. World Wide Web, pp. 148-159, May 2003.
    • (2003) Proc. 12th Int'l Conf. World Wide Web , pp. 148-159
    • Huang, Y.1    Huang, S.2    Lin, T.3    Tsai, C.4
  • 18
    • 84923564816 scopus 로고    scopus 로고
    • Finding Security Vulnerabilities in Java Applications with Static Analysis
    • Aug
    • V.B. Livshits and M.S. Lam, "Finding Security Vulnerabilities in Java Applications with Static Analysis," Proc. 14th Usenix Security Symp. Aug. 2005.
    • (2005) Proc. 14th Usenix Security Symp
    • Livshits, V.B.1    Lam, M.S.2
  • 19
    • 40449087507 scopus 로고    scopus 로고
    • O. Maor and A. Shulman, SQL Injection Signatures Evasion, white paper, Imperva, http://www.imperva.com/application-defense_center/ white_papers/sql_injection_signatures_evasion.html, Apr. 2004.
    • O. Maor and A. Shulman, "SQL Injection Signatures Evasion," white paper, Imperva, http://www.imperva.com/application-defense_center/ white_papers/sql_injection_signatures_evasion.html, Apr. 2004.
  • 21
    • 33244471315 scopus 로고    scopus 로고
    • R. McClure and 1. Kr6ger, SQL DOM: Compile Time Checking of Dynamic SQL Statements, Proc. 27th Int'l Conf. Software Eng., pp. 88-96, May 2005.
    • R. McClure and 1. Kr6ger, "SQL DOM: Compile Time Checking of Dynamic SQL Statements," Proc. 27th Int'l Conf. Software Eng., pp. 88-96, May 2005.
  • 22
    • 79953672829 scopus 로고    scopus 로고
    • Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software
    • Feb
    • J. Newsome and D. Song, "Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software," Proc. 12th Ann. Network and Distributed System Security Symp., Feb. 2005.
    • (2005) Proc. 12th Ann. Network and Distributed System Security Symp
    • Newsome, J.1    Song, D.2
  • 30
    • 84910681237 scopus 로고    scopus 로고
    • Static Detection of Security Vulnerabilities in Scripting Languages
    • Aug
    • Y. Xie and A. Aiken, "Static Detection of Security Vulnerabilities in Scripting Languages," Proc. 15th Usenix Security Symp., Aug. 2006.
    • (2006) Proc. 15th Usenix Security Symp
    • Xie, Y.1    Aiken, A.2
  • 31
    • 85038810709 scopus 로고    scopus 로고
    • Taint-Enhanced Policy Enforcement: A Practical Approach to Defeat a Wide Range of Attacks
    • Aug
    • W. Xu, S. Bhatkar, and R. Sekar, "Taint-Enhanced Policy Enforcement: A Practical Approach to Defeat a Wide Range of Attacks," Proc. 15th Usenix Security Symp., Aug. 2006.
    • (2006) Proc. 15th Usenix Security Symp
    • Xu, W.1    Bhatkar, S.2    Sekar, R.3


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.