Static Detection Of Security Vulnerabilities In Scripting Languages

USENIX-SS'06: Proceedings of the 15th conference on USENIX Security Symposium - Volume 15(2006)

引用 548|浏览459
暂无评分
摘要
We present a static analysis algorithm for detecting security vulnerabilities in PHP, a popular server-side scripting language for building web applications. Our analysis employs a novel three-tier architecture to capture information at decreasing levels of granularity at the intrablock, intraprocedural, and interprocedural level. This architecture enables us to handle dynamic features of scripting languages that have not been adequately addressed by previous techniques.We demonstrate the effectiveness of our approach on six popular open source PHP code bases, finding 105 previously unknown security vulnerabilities, most of which we believe are remotely exploitable.
更多
查看译文
关键词
novel three-tier architecture,popular open source PHP,popular server-side,scripting language,security vulnerability,static analysis algorithm,unknown security vulnerability,code base,dynamic feature,interprocedural level,static detection
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要