메뉴 건너뛰기




Volumn 18, Issue 5, 2010, Pages 861-907

Static analysis for detecting taint-style vulnerabilities in web applications

Author keywords

alias analysis; cross site scripting; data flow analysis; PHP; Program analysis; scripting languages security; SQL injection; static analysis; web application security

Indexed keywords

ALIAS ANALYSIS; CROSS SITE SCRIPTING; DATA FLOW; PHP; PROGRAM ANALYSIS; SCRIPTING LANGUAGES; SQL INJECTION; WEB APPLICATION SECURITY;

EID: 77957112438     PISSN: 0926227X     EISSN: None     Source Type: Journal    
DOI: 10.3233/JCS-2009-0385     Document Type: Article
Times cited : (49)

References (46)
  • 3
    • 65349145047 scopus 로고    scopus 로고
    • Using programmer-written compiler extensions to catch security holes
    • Oakland, CA, USA
    • K. Ashcraft and D. Engler, Using programmer-written compiler extensions to catch security holes, in: IEEE Symposium on Security and Privacy, Oakland, CA, USA, 2002.
    • (2002) IEEE Symposium on Security and Privacy
    • Ashcraft, K.1    Engler, D.2
  • 4
    • 77957110564 scopus 로고    scopus 로고
    • BugTraqr, BugTraq Mailing List Archive, 2005, http://www.securityfocus. com/archive/1.
    • (2005) BugTraqr
  • 10
    • 84975277890 scopus 로고    scopus 로고
    • Checking system rules using system-specific, programmer-written compiler extensions
    • Denver, CO, USA
    • D. Engler, B. Chelf, A. Chou and S. Hallem, Checking system rules using system-specific, programmer-written compiler extensions, in: OSDI 2000, Denver, CO, USA, 2000.
    • (2000) OSDI 2000
    • Engler, D.1    Chelf, B.2    Chou, A.3    Hallem, S.4
  • 17
    • 4544358830 scopus 로고    scopus 로고
    • Verifying web applications using bounded model checking
    • Florence, Italy
    • Y.-W. Huang, F. Yu, C. Hang, C.-H. Tsai, D.-T. Lee and S.-Y. Kuo, Verifying web applications using bounded model checking, in: DSN, Florence, Italy, 2004.
    • (2004) DSN
    • Huang, Y.-W.1    Yu, F.2    Hang, C.3    Tsai, C.-H.4    Lee, D.-T.5    Kuo, S.-Y.6
  • 19
    • 85084161650 scopus 로고    scopus 로고
    • Finding user/kernel pointer bugs with type inference
    • San Diego, CA, USA
    • R. Johnson and D. Wagner, Finding user/kernel pointer bugs with type inference, in: 13th USENIX Security Symposium, San Diego, CA, USA, 2004.
    • (2004) 13th USENIX Security Symposium
    • Johnson, R.1    Wagner, D.2
  • 20
    • 33751027156 scopus 로고    scopus 로고
    • Pixy: A static analysis tool for detecting web application vulnerabilities (short paper)
    • Oakland, CA, USA
    • N. Jovanovic, C. Kruegel and E. Kirda, Pixy: A static analysis tool for detecting web application vulnerabilities (Short paper), in: IEEE Symposium on Security and Privacy, Oakland, CA, USA, 2006.
    • (2006) IEEE Symposium on Security and Privacy
    • Jovanovic, N.1    Kruegel, C.2    Kirda, E.3
  • 31
    • 77957115832 scopus 로고    scopus 로고
    • PAG/WWW: Static program analysis, 2005, http://www.program-analysis.com.
    • (2005)
  • 33
    • 33745933622 scopus 로고    scopus 로고
    • Defending against injection attacks through context-sensitive string evaluation
    • Seattle, WA, USA
    • T. Pietraszek and C.V. Berghe, Defending against injection attacks through context-sensitive string evaluation, in: Recent Advances in Intrusion Detection 2005 (RAID), Seattle, WA, USA, 2005.
    • (2005) Recent Advances in Intrusion Detection 2005 (RAID)
    • Pietraszek, T.1    Berghe, C.V.2
  • 34
    • 77957114449 scopus 로고    scopus 로고
    • Secure Systems Lab, Technical University of Vienna, 2006, http://www.seclab.tuwien.ac.at.
    • (2006)
  • 37
    • 84860028991 scopus 로고    scopus 로고
    • available at
    • S. Shankland, Andreessen: PHP succeeding where Java isn't, 2005, available at: http://www.zdnet. com.au/news/software/soa/Andreessen-PHP- succeeding-where-Java-isn-t/0,2000061733,392181 71,00.htm.
    • (2005) Andreessen: Php Succeeding where Java Isn't
    • Shankland, S.1
  • 44
    • 84859282631 scopus 로고    scopus 로고
    • Wikipedia, Hasse diagram, 2005, http://en.wikipedia.org/wiki/Hasse- diagram.
    • (2005) Wikipedia
  • 46
    • 84910681237 scopus 로고    scopus 로고
    • Static detection of security vulnerabilities in scripting languages
    • Vancouver, BC, Canada
    • Y. Xie and A. Aiken, Static detection of security vulnerabilities in scripting languages, in: Proceedings of the 15th USENIX Security Symposium, Vancouver, BC, Canada, 2006.
    • (2006) Proceedings of the 15th USENIX Security Symposium
    • Xie, Y.1    Aiken, A.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.