跳到主要导航 跳到搜索 跳到主要内容

Program slicing stored XSS bugs in web application

  • Yi Wang*
  • , Zhoujun Li
  • , Tao Guo
  • *此作品的通讯作者
  • Beihang University
  • China Information Technology Security Evaluation Center

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Web applications are vulnerable targets of security attacks. Among the well known attack type - XSS(Cross-Site Scripting), the most threatening is Stored XSS. Since most static analysis methods refer to Reflected XSS but few concentrate on Stored XSS which is more devastating, plus the fact that pure static analysis offers high false positive rate, we present a static Stored XSS detection algorithm integrated with program slicing method to generate the slices of web application related to possible Stored XSS. The slices are composed of two parts, threat injection and threat release, which reconstruct a Stored XSS attack scenario. They are of great value for later manual checking or other dynamic analysis. For manual checking, the programmer can directly check the code related to possible vulnerabilities. For dynamic analysis or model checking, the program coverage can be large or even complete because of the small size of these slices.

源语言英语
主期刊名Proceedings - 5th International Conference on Theoretical Aspects of Software Engineering, TASE 2011
191-194
页数4
DOI
出版状态已出版 - 2011
活动5th International Conference on Theoretical Aspects of Software Engineering, TASE 2011 - Xi'an, Shaanxi, 中国
期限: 29 8月 201131 8月 2011

出版系列

姓名Proceedings - 5th International Conference on Theoretical Aspects of Software Engineering, TASE 2011

会议

会议5th International Conference on Theoretical Aspects of Software Engineering, TASE 2011
国家/地区中国
Xi'an, Shaanxi
时期29/08/1131/08/11

指纹

探究 'Program slicing stored XSS bugs in web application' 的科研主题。它们共同构成独一无二的指纹。

引用此