Paper
11 October 2023 A method to web application taint analysis by computing data dependency
Lifei Xu, Yunshan Tang, Haoli Chen
Author Affiliations +
Proceedings Volume 12800, Sixth International Conference on Computer Information Science and Application Technology (CISAT 2023); 128005P (2023) https://doi.org/10.1117/12.3003984
Event: 6th International Conference on Computer Information Science and Application Technology (CISAT 2023), 2023, Hangzhou, China
Abstract
As software plays an increasingly critical role in production life, software security issues are gaining more and more attention. Static taint analysis technology is one of the most widely used information flow analysis techniques, and the simulation of the dynamic characteristics of the detected objects has been a difficult point of research. In this paper, we propose a construction scheme based on demand-driven data dependency calculation for the dynamic response problem of Web back-end application processor method, and simulate the invocation relationship that cannot be revealed on the static control flow graph. The solution was then implemented with the help of Soot framework to perform SQL injection detection for web back-end applications and verified in comparison with the current detection tools.
(2023) Published by SPIE. Downloading of the abstract is permitted for personal use only.
Lifei Xu, Yunshan Tang, and Haoli Chen "A method to web application taint analysis by computing data dependency", Proc. SPIE 12800, Sixth International Conference on Computer Information Science and Application Technology (CISAT 2023), 128005P (11 October 2023); https://doi.org/10.1117/12.3003984
Advertisement
Advertisement
RIGHTS & PERMISSIONS
Get copyright permission  Get copyright permission on Copyright Marketplace
KEYWORDS
Contamination

Data acquisition

Computer simulations

Statistical analysis

Analytical research

Reflection

Computer security

Back to Top