English  |  正體中文  |  简体中文  |  Post-Print筆數 : 27 |  Items with full text/Total items : 95843/126433 (76%)
Visitors : 31606062      Online Users : 571
RC Version 6.0 © Powered By DSPACE, MIT. Enhanced by NTU Library IR team.
Scope Tips:
  • please add "double quotation mark" for query phrases to get precise results
  • please goto advance search for comprehansive author search
  • Adv. Search
    HomeLoginUploadHelpAboutAdminister Goto mobile version
    政大機構典藏 > 商學院 > 資訊管理學系 > 會議論文 >  Item 140.119/78009
    Please use this identifier to cite or link to this item: http://nccur.lib.nccu.edu.tw/handle/140.119/78009

    Title: Patching vulnerabilities with sanitization synthesis
    Authors: Yu, Fang;Alkhalaf, Muath;Bultan, Tevfik
    Contributors: 資訊管理學系
    Keywords: Sanitization Synthesis;String Analysis;Automata
    Date: 2011-05
    Issue Date: 2015-08-27 17:34:57 (UTC+8)
    Abstract: We present automata-based static string analysis techniques that automatically generate sanitization statements for patching vulnerable web applications. Our approach consists of three phases: Given an attack pattern we first conduct a vulnerability analysis to identify if strings that match the attack pattern can reach the security-sensitive functions. Next, we compute vulnerability signatures that characterize all input strings that can exploit the discovered vulnerability. Given the vulnerability signatures, we then construct sanitization statements that 1) check if a given input matches the vulnerability signature and 2) modify the input in a minimal way so that the modified input does not match the vulnerability signature. Our approach is capable of generating relational vulnerability signatures (and corresponding sanitization statements) for vulnerabilities that are due to more than one input.
    Relation: ICSE '11 Proceedings of the 33rd International Conference on Software Engineering,251-260
    Data Type: conference
    DOI 連結: http://dx.doi.org/10.1145/1985793.1985828
    DOI: 10.1145/1985793.1985828
    Appears in Collections:[資訊管理學系] 會議論文

    Files in This Item:

    File Description SizeFormat
    251-260.pdf997KbAdobe PDF576View/Open

    All items in 政大典藏 are protected by copyright, with all rights reserved.

    社群 sharing

    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library IR team Copyright ©   - Feedback