Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
Ergebnis 4 von 13
Proceedings of the 25th International Symposium on Software Testing and Analysis, 2016, p.189-200
2016

Details

Autor(en) / Beteiligte
Titel
Optimal sanitization synthesis for web application vulnerability repair
Ist Teil von
  • Proceedings of the 25th International Symposium on Software Testing and Analysis, 2016, p.189-200
Ort / Verlag
New York, NY, USA: ACM
Erscheinungsjahr
2016
Link zum Volltext
Quelle
ACM Digital Library Complete
Beschreibungen/Notizen
  • We present a code- and input-sensitive sanitization synthesis approach for repairing string vulnerabilities that are common in web applications. The synthesized sanitization patch modifies the user input in an optimal way while guaranteeing that the repaired web application is not vulnerable. Given a web application, an input pattern and an attack pattern, we use automata-based static string analysis techniques to compute a sanitization signature that characterizes safe input values that obey the given input pattern and are safe with respect to the given attack pattern. Using the sanitization signature, we synthesize an optimal sanitization patch that converts malicious user inputs to benign ones with minimal editing. When the generated patch is added to the web application, it is guaranteed that the repaired web application is no longer vulnerable. We present refinements to previous sanitization synthesis algorithms that reduce the runtime sanitization cost significantly. We evaluate our approach on open source web applications using common input and attack patterns, demonstrating the effectiveness of our approach.
Sprache
Englisch
Identifikatoren
ISBN: 9781450343909, 1450343902
DOI: 10.1145/2931037.2931050
Titel-ID: cdi_acm_books_10_1145_2931037_2931050

Weiterführende Literatur

Empfehlungen zum selben Thema automatisch vorgeschlagen von bX