New Method for Detecting Code Security Vulnerability Based on Reverse Deduction with Proof-Tree
|更新时间:2025-12-08
|
New Method for Detecting Code Security Vulnerability Based on Reverse Deduction with Proof-Tree
Vol. 41, Issue 4, Pages: 439-443(2007)
作者机构:
1. 西安交通大学智能网络与网络安全教育部重点实验室,西安,710049
2. 西安交通大学机械制造系统工程国家重点实验室,西安,710049
作者简介:
基金信息:
DOI:
CLC:TP393
Online First:10 April 2007,
Published:2007
稿件说明:
移动端阅览
王清 1, 郑庆华 1, 管晓宏 1, et al. New Method for Detecting Code Security Vulnerability Based on Reverse Deduction with Proof-Tree[J]. 2007, 41(4): 439-443.
DOI:
王清 1, 郑庆华 1, 管晓宏 1, et al. New Method for Detecting Code Security Vulnerability Based on Reverse Deduction with Proof-Tree[J]. 2007, 41(4): 439-443.DOI:
New Method for Detecting Code Security Vulnerability Based on Reverse Deduction with Proof-Tree
a method for detecting SQL injection vulnerabilities which are ubiquitous in Web applications is presented. Differing from traditional real time security strategies such as IDS and firewall
the origin of producing attack can be found by directly mining source codes vulnerabilities. The essentials are to track reversely the variables that are related to database(DB)script operations and check whether they are influenced from outside so as to control the hidden damage existing in the DB operations. The experimental results show that the proposed method can accurately verify the security of 53.8% DB operations
and it is applicable for any type of Web application platforms configured with different script languages and database systems.
关键词
Keywords
references
Pietraszek T, Berge C V. Defending against injection attacks through context-sensitive string evaluation [C]∥8th International Symposium on Recent Advances in Intrusion Detection. Berlin: Springer-Verlag, 2006:124-145.
Buehrer G T, Bruce W. Using parse TreeValidation to prevent SQL injection attacks [C]∥Proceedings of the 5th international Workshop on Software Engineering and Middleware. New York:ACM, 2005:106-113.
Fosdick L D, Osterweil L J. Data flow analysis in software reliability [J]. Computing Surveys, 1976,8(3):305-330.
Gustafsson J, Lisper B. A tool for automatic flow analysis of C-programs for WCET calculation [C]∥8th IEEE International Workshop on Object-Oriented Real-Time Dependable Systems. Piscataway, USA: IEEE, 2003:106-112.
Walker D. A type system for expressive security policies [C]∥Proceedings of the 27th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages. New York: ACM, 2000:254-267.