Removal of Web Application Vulnerabilities using Taint Analyzer and Code Corrector

Shafaque Fatma Syed, Aamir Ahmed, G. D'Mello, Zeeshan Ansari
{"title":"Removal of Web Application Vulnerabilities using Taint Analyzer and Code Corrector","authors":"Shafaque Fatma Syed, Aamir Ahmed, G. D'Mello, Zeeshan Ansari","doi":"10.1109/ICNTE44896.2019.8945976","DOIUrl":null,"url":null,"abstract":"Security has been a challenging aspect recently in the field of Web Development. A failure to obtain security in web applications may lead to complete destruction of the web application or may cause some loss to the user or the owner. To tackle this, a huge research on how to secure a web app has been going on for quite some time, yet to achieve security in today's modern era is a very difficult and no less than a challenge for web applications. All these things lead only to a vulnerable/faulty source code, formulated in coding such as PHP. Static Source Code analysis (SCSA) tools tend to give a solution to detect vulnerabilities, but they tend to detect vulnerabilities which actually are false positives, which leads to excess code reexamination. The proposed system will tackle the current situation of SCSA. This will be achieved by two additional modules to SCSA i.e. Taint analysis with False Positive Predictor which will detect and segregate the true vulnerable code from false positives respectively. The proposed system will be used by the Web Application programmers during testing of web application.","PeriodicalId":292408,"journal":{"name":"2019 International Conference on Nascent Technologies in Engineering (ICNTE)","volume":"41 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 International Conference on Nascent Technologies in Engineering (ICNTE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICNTE44896.2019.8945976","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Security has been a challenging aspect recently in the field of Web Development. A failure to obtain security in web applications may lead to complete destruction of the web application or may cause some loss to the user or the owner. To tackle this, a huge research on how to secure a web app has been going on for quite some time, yet to achieve security in today's modern era is a very difficult and no less than a challenge for web applications. All these things lead only to a vulnerable/faulty source code, formulated in coding such as PHP. Static Source Code analysis (SCSA) tools tend to give a solution to detect vulnerabilities, but they tend to detect vulnerabilities which actually are false positives, which leads to excess code reexamination. The proposed system will tackle the current situation of SCSA. This will be achieved by two additional modules to SCSA i.e. Taint analysis with False Positive Predictor which will detect and segregate the true vulnerable code from false positives respectively. The proposed system will be used by the Web Application programmers during testing of web application.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
使用污点分析器和代码校正器去除Web应用程序漏洞
在Web开发领域,安全性一直是一个具有挑战性的方面。如果web应用程序无法获得安全保护,可能会导致web应用程序的彻底破坏,或者给用户或所有者造成一定的损失。为了解决这个问题,关于如何保护web应用程序的大量研究已经进行了相当长的一段时间,然而在当今的现代时代实现安全性是非常困难的,对web应用程序来说不亚于一个挑战。所有这些只会导致易受攻击/有缺陷的源代码,在PHP等编码中进行表述。静态源代码分析(SCSA)工具倾向于提供检测漏洞的解决方案,但它们倾向于检测实际上是误报的漏洞,这会导致过多的代码重新检查。建议的制度将会处理公务员津贴的现状。这将通过SCSA的两个额外模块来实现,即带有假阳性预测器的污点分析,它将分别检测和分离真实的易受攻击代码和假阳性。该系统将供Web应用程序开发人员在Web应用程序测试期间使用。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Web Application for Screening Resume Top-Down Approach in Design and Simulation of Grid Integrated Solar Rooftop PV System Design Considerations and Simulation of Superconducting Transformers Portal Based Prepaid Energy Billing System Using GSM Smart Recommendation System Based on Product Reviews Using Random Forest
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1