跳至主導覽 跳至搜尋 跳過主要內容

Securing web application code by static analysis and runtime protection

  • Yao Wen Huang*
  • , Fang Yu
  • , Christian Hang
  • , Chung Hung Tsai
  • , D. T. Lee
  • , Sy Yen Kuo
  • *此作品的通信作者
  • National Taiwan University
  • Academia Sinica - Institute of Information Science
  • RWTH Aachen University

研究成果: 圖書/報告稿件的類型會議稿件同行評審

413 引文 斯高帕斯(Scopus)

摘要

Security remains a major roadblock to universal acceptance of the Web for many kinds of transactions, especially since the recent sharp increase in remotely exploitable vulnerabilities has been attributed to Web application bugs. Many verification tools are discovering previously unknown vulnerabilities in legacy C programs, raising hopes that the same success can be achieved with Web applications. In this paper, we describe a sound and holistic approach to ensuring Web application security. Viewing Web application vulnerabilities as a secure information flow problem, we created a lattice-based static analysis algorithm derived from type systems and typestate, and addressed its soundness. During the analysis, sections of code considered vulnerable are instrumented with runtime guards, thus securing Web applications in the absence of user intervention. With sufficient annotations, runtime overhead can be reduced to zero. We also created a tool named WebSSARI (Web application Security by Static Analysis and Runtime Inspection) to test our algorithm, and used it to verify 230 open-source Web application projects on SourceForge.net, which were selected to represent projects of different maturity, popularity, and scale. 69 contained vulnerabilities and their developers were notified. 38 projects acknowledged our findings and stated their plans to provide patches. Our statistics also show that static analysis reduced potential runtime overhead by 98.4%.

原文英語
主出版物標題Thirteenth International World Wide Web Conference Proceedings, WWW2004
發行者Association for Computing Machinery (ACM)
頁面40-52
頁數13
ISBN(列印)158113844X, 9781581138443
DOIs
出版狀態已出版 - 2004
對外發佈
事件Thirteenth International World Wide Web Conference Proceedings, WWW2004 - New York, NY, 美國
持續時間: 17 05 200422 05 2004

出版系列

名字Thirteenth International World Wide Web Conference Proceedings, WWW2004

Conference

ConferenceThirteenth International World Wide Web Conference Proceedings, WWW2004
國家/地區美國
城市New York, NY
期間17/05/0422/05/04

指紋

深入研究「Securing web application code by static analysis and runtime protection」主題。共同形成了獨特的指紋。

引用此