메뉴 건너뛰기




Volumn , Issue , 2012, Pages 100-109

Supporting automated vulnerability analysis using formalized vulnerability signatures

Author keywords

Common weaknesses enumeration (CWE); Formal vulnerability specification; Software security; Vulnerability analysis

Indexed keywords

BENCHMARK APPLICATIONS; COMMON WEAKNESSES ENUMERATION (CWE); IT SYSTEM; PROGRAM ANALYSIS; REACHABILITY; SECURITY REQUIREMENTS; SOFTWARE SECURITY; TARGET SYSTEMS; VULNERABILITY ANALYSIS; VULNERABILITY SIGNATURE; WEB APPLICATION; PUBLICLY ACCESSIBLE;

EID: 84866913797     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/2351676.2351691     Document Type: Conference Paper
Times cited : (31)

References (22)
  • 1
    • 50249115131 scopus 로고    scopus 로고
    • Saner: Composing static and dynamic analysis to validate sanitization in web applications
    • BALZAROTTI, D., COVA, et al 2008. Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications. In Proc. of 2008 IEEE Symposium on Security and Privacy, 387-401.
    • (2008) Proc. of 2008 IEEE Symposium on Security and Privacy , pp. 387-401
    • Balzarotti, D.1    Cova2
  • 3
    • 33644662135 scopus 로고    scopus 로고
    • OCL 1.4/5 vs. 2.0 expressions formal semantics and expressiveness
    • CENGARLE, M.V. and KNAPP, A., 2004. OCL 1.4/5 vs. 2.0 Expressions Formal semantics and expressiveness. Software and Systems Modeling 3, 1, 9-30.
    • (2004) Software and Systems Modeling , vol.3 , Issue.1 , pp. 9-30
    • Cengarle, M.V.1    Knapp, A.2
  • 5
    • 84894088425 scopus 로고    scopus 로고
    • Toward automated detection of logic vulnerabilities in web applications
    • Washington, DC
    • FELMETSGER, V., et al, 2010. Toward automated detection of logic vulnerabilities in web applications. In 19th USENIX Conf. on Security, Washington, DC.
    • (2010) 19th USENIX Conf. on Security
    • Felmetsger, V.1
  • 8
    • 84970882954 scopus 로고    scopus 로고
    • Fast and precise sanitizer analysis with BEK
    • San Francisco, CA2011
    • HOOIMEIJER, P., et al, 2011. Fast and precise sanitizer analysis with BEK. In 20th USENIX Conf. on Security (San Francisco, CA2011).
    • (2011) 20th USENIX Conf. on Security
    • Hooimeijer, P.1
  • 9
    • 33751027156 scopus 로고    scopus 로고
    • Pixy: A static analysis tool for detecting Web application vulnerabilities
    • JOVANOVIC, N., KRUEGEL, C., et al, 2006. Pixy: a static analysis tool for detecting Web application vulnerabilities. In 2006 IEEE Symposium on Security and Privacy, 258-263.
    • (2006) 2006 IEEE Symposium on Security and Privacy , pp. 258-263
    • Jovanovic, N.1    Kruegel, C.2
  • 10
    • 34250673645 scopus 로고    scopus 로고
    • SecuBat: A web vulnerability scanner
    • Edinburgh
    • KALS, S., et al, 2006. SecuBat: a web vulnerability scanner. In 15th Int. Conf. on World Wide Web. Edinburgh, 247-256.
    • (2006) 15th Int. Conf. on World Wide Web. , pp. 247-256
    • Kals, S.1
  • 11
    • 77949879017 scopus 로고    scopus 로고
    • Automatic creation of SQL Injection and cross-site scripting attacks
    • KIEYZUN, et al, 2009. Automatic creation of SQL Injection and cross-site scripting attacks. In Proc. of 31st Int.Conf. on Software Engineering, 199-209.
    • (2009) Proc. of 31st Int.Conf. on Software Engineering , pp. 199-209
    • Kieyzun1
  • 18
    • 57349153984 scopus 로고    scopus 로고
    • Static detection of cross-site scripting vulnerabilities
    • Leipzig, Germany
    • WASSERMANN, G. and SU, Z., 2008. Static detection of cross-site scripting vulnerabilities. In Proc. 30th Int. Conf. on Software engineering ACM, Leipzig, Germany, 171-180.
    • (2008) Proc. 30th Int. Conf. on Software Engineering ACM , pp. 171-180
    • Wassermann, G.1    Su, Z.2
  • 21
    • 84855442829 scopus 로고    scopus 로고
    • Static program analysis assisted dynamic taint tracking for software vulnerability discovery
    • ZHANG, R., HUANG, S., et al, 2012. Static program analysis assisted dynamic taint tracking for software vulnerability discovery. Computers & Mathematics with Application 63, 2, 469-480.
    • (2012) Computers & Mathematics with Application , vol.63 , Issue.2 , pp. 469-480
    • Zhang, R.1    Huang, S.2
  • 22
    • 84866924976 scopus 로고    scopus 로고
    • An Incremental OCL Compiler for Modelling Environments
    • OCL Concepts and Tools
    • VAJK, T., MEZEI, G., and LEVEDOVSZKY T., 2008. An Incremental OCL Compiler for Modelling Environments. In Electronic Communications of the EASST, vol. Volume 15: OCL Concepts and Tools.
    • (2008) Electronic Communications of the EASST , vol.15
    • Vajk, T.1    Mezei, G.2    Levedovszky, T.3


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.