Mining SQL injection and cross site scripting vulnerabilities using hybrid program analysis

LK Shar, HBK Tan, LC Briand - 2013 35th International …, 2013 - ieeexplore.ieee.org
In previous work, we proposed a set of static attributes that characterize input validation and
input sanitization code patterns. We showed that some of the proposed static attributes are
significant predictors of SQL injection and cross site scripting vulnerabilities. Static attributes
have the advantage of reflecting general properties of a program. Yet, dynamic attributes
collected from execution traces may reflect more specific code characteristics that are
complementary to static attributes. Hence, to improve our initial work, in this paper, we …

[PDF][PDF] Mining SQL injection and cross site scripting vulnerabilities using hybrid program analysis.(2013)

LK Shar, HBK TAN, LC BRIAND - Proceedings of the 35th ACM/IEEE …, 2013 - core.ac.uk
In previous work, we proposed a set of static attributes that characterize input validation and
input sanitization code patterns. We showed that some of the proposed static attributes are
significant predictors of web application vulnerabilities related to SQL injection and cross
site scripting. Static attributes have the advantage of reflecting general properties of a
program. Yet, dynamic attributes collected from execution traces may reflect more specific
code characteristics that are complementary to static attributes. Hence, to improve our initial …
以上显示的是最相近的搜索结果。 查看全部搜索结果