• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Wang, Yaohui (Wang, Yaohui.) | Wang, Dan (Wang, Dan.) | Zhao, Wenbing (Zhao, Wenbing.) | Liu, Yuan (Liu, Yuan.)

收录:

CPCI-S Scopus

摘要:

Targeting at PHP program, this paper proposes an SQL vulnerability detection method based on the injection analysis technology. This method makes a detailed analysis on the one-time injection in the aspects of data flow and program behavior, on the basis of the combination of dynamic and static analysis technique. Then it implements the SQL vulnerability determination algorithm which is based on lexical feature comparison. At last, this paper combines alias analysis technology, behavior model and SQL which is based on lexical feature comparison to design and establish a prototype system for SQL vulnerability detection. The experiment shows that our system has a good strong ability of SQL vulnerability detection and very low time cost.

关键词:

SQL vulnerabilities combination of static and dynamic technique behavior model alias analysis

作者机构:

  • [ 1 ] [Wang, Yaohui]Beijing Univ Technol, Beijing, Peoples R China
  • [ 2 ] [Wang, Dan]Beijing Univ Technol, Beijing, Peoples R China
  • [ 3 ] [Zhao, Wenbing]Beijing Univ Technol, Beijing, Peoples R China
  • [ 4 ] [Liu, Yuan]Beijing Univ Technol, Beijing, Peoples R China

通讯作者信息:

  • [Wang, Yaohui]Beijing Univ Technol, Beijing, Peoples R China

电子邮件地址:

查看成果更多字段

相关关键词:

相关文章:

来源 :

IEEE 39TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC 2015), VOL 3

ISSN: 0730-3157

年份: 2015

页码: 604-607

语种: 英文

被引次数:

WoS核心集被引频次: 8

SCOPUS被引频次: 13

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 4

归属院系:

在线人数/总访问数:125/4299917
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司