王清 1, 郑庆华 1, 管晓宏 1, et al. New Method for Detecting Code Security Vulnerability Based on Reverse Deduction with Proof-Tree[J]. 2007, 41(4): 439-443.DOI:
a method for detecting SQL injection vulnerabilities which are ubiquitous in Web applications is presented. Differing from traditional real time security strategies such as IDS and firewall
the origin of producing attack can be found by directly mining source codes vulnerabilities. The essentials are to track reversely the variables that are related to database(DB)script operations and check whether they are influenced from outside so as to control the hidden damage existing in the DB operations. The experimental results show that the proposed method can accurately verify the security of 53.8% DB operations
and it is applicable for any type of Web application platforms configured with different script languages and database systems.
关键词
Keywords
references
Pietraszek T, Berge C V. Defending against injection attacks through context-sensitive string evaluation [C]∥8th International Symposium on Recent Advances in Intrusion Detection. Berlin: Springer-Verlag, 2006:124-145.
Buehrer G T, Bruce W. Using parse TreeValidation to prevent SQL injection attacks [C]∥Proceedings of the 5th international Workshop on Software Engineering and Middleware. New York:ACM, 2005:106-113.
Fosdick L D, Osterweil L J. Data flow analysis in software reliability [J]. Computing Surveys, 1976,8(3):305-330.
Gustafsson J, Lisper B. A tool for automatic flow analysis of C-programs for WCET calculation [C]∥8th IEEE International Workshop on Object-Oriented Real-Time Dependable Systems. Piscataway, USA: IEEE, 2003:106-112.
Walker D. A type system for expressive security policies [C]∥Proceedings of the 27th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages. New York: ACM, 2000:254-267.