Please use this identifier to cite or link to this item: https://ah.lib.nccu.edu.tw/handle/140.119/78009
DC FieldValueLanguage
dc.contributor資訊管理學系
dc.creatorYu, Fang;Alkhalaf, Muath;Bultan, Tevfik
dc.creator郁方zh_TW
dc.date2011-05
dc.date.accessioned2015-08-27T09:34:57Z-
dc.date.available2015-08-27T09:34:57Z-
dc.date.issued2015-08-27T09:34:57Z-
dc.identifier.urihttp://nccur.lib.nccu.edu.tw/handle/140.119/78009-
dc.description.abstractWe present automata-based static string analysis techniques that automatically generate sanitization statements for patching vulnerable web applications. Our approach consists of three phases: Given an attack pattern we first conduct a vulnerability analysis to identify if strings that match the attack pattern can reach the security-sensitive functions. Next, we compute vulnerability signatures that characterize all input strings that can exploit the discovered vulnerability. Given the vulnerability signatures, we then construct sanitization statements that 1) check if a given input matches the vulnerability signature and 2) modify the input in a minimal way so that the modified input does not match the vulnerability signature. Our approach is capable of generating relational vulnerability signatures (and corresponding sanitization statements) for vulnerabilities that are due to more than one input.
dc.format.extent1021848 bytes-
dc.format.mimetypeapplication/pdf-
dc.relationICSE `11 Proceedings of the 33rd International Conference on Software Engineering,251-260
dc.subjectSanitization Synthesis;String Analysis;Automata
dc.titlePatching vulnerabilities with sanitization synthesis
dc.typeconferenceen
dc.identifier.doi10.1145/1985793.1985828
dc.doi.urihttp://dx.doi.org/10.1145/1985793.1985828
item.grantfulltextopen-
item.cerifentitytypePublications-
item.fulltextWith Fulltext-
item.openairecristypehttp://purl.org/coar/resource_type/c_18cf-
item.openairetypeconference-
Appears in Collections:會議論文
Files in This Item:
File Description SizeFormat
251-260.pdf997.9 kBAdobe PDF2View/Open
Show simple item record

Google ScholarTM

Check

Altmetric

Altmetric


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.