已入深夜,您辛苦了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!祝你早点完成任务,早点休息,好梦!

DetAC: Approach to Detect Access Control Vulnerability in Web Application Based on Sitemap Model with Global Information Representation

计算机科学 访问控制 静态分析 脆弱性(计算) 源代码 网页 基于角色的访问控制 信息泄露 数据挖掘 计算机安全 万维网 操作系统 程序设计语言
作者
Jiadong Ren,Mingyou Wu,Bing Zhang,Ke Xu,Shangyang Li,Qian Wang,Yue Chang,Tao Cheng
出处
期刊:International Journal of Software Engineering and Knowledge Engineering [World Scientific]
卷期号:33 (09): 1327-1354 被引量:1
标识
DOI:10.1142/s0218194023500298
摘要

Access control vulnerabilities that lead to elevated privileges are among the most dangerous vulnerabilities in Web applications. Most of the existing detection methods use dynamic or static analysis techniques alone, which suffer from high manual involvement, low automation, high leakage rate, low page coverage, and other deficiencies. To this end, this paper proposes a novel access control vulnerability detection method (DetAC) based on a sitemap model with global information representation. This method first constructs a static site-wide sitemap model based on the page link addresses in the Web application source code through static analysis techniques. After that, the application is logged in and executed dynamically with different role users. During this process, execution traces and request parameters are collected and converted into annotations to fill the corresponding edges of the static site-wide sitemap model. Then, the sitemap model with global information representation is obtained. This model can represent both the global control flow and data flow of the application. Then DetAC analyzes the role-based and user-based access control policies of the Web application based on the node reachability and annotated data features of the model. And according to the information such as role, user, and access resources, it generates attack vectors to achieve different roles and the same role of different users to access each other’s resources. Finally, access control vulnerabilities are detected based on the equivalence of the results obtained using attack vector access and normal access to the Web application server. DetAC was validated on five real open-source Web applications, and the results showed that DetAC successfully detected up to 12 access control vulnerabilities, which are more than those of the traditional seven tools. The dynamic analysis page coverage rate was significantly improved during the detection process, reaching an average of 91.37%.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
Xc的应助被敏感的烧鹅采纳,获得10
刚刚
史萌发布了新的文献求助10
1秒前
dsafas的应助被sx采纳,获得10
2秒前
传奇3的应助被洁净笑白采纳,获得10
2秒前
鳗鱼颖发布了新的文献求助10
2秒前
lza完成签到,获得积分20
3秒前
xiaozi发布了新的文献求助10
3秒前
七月流火的应助被橙澄诚采纳,获得100
3秒前
3秒前
4秒前
快乐代灵完成签到,获得积分10
6秒前
斯尼奇发布了新的文献求助10
6秒前
6秒前
宦邶发布了新的文献求助10
7秒前
风中的天蓝完成签到 ,获得积分10
8秒前
Ava的应助被香蕉幻桃采纳,获得10
8秒前
yanzi发布了新的文献求助10
10秒前
10秒前
10秒前
傲人男根完成签到,获得积分10
11秒前
tzy发布了新的文献求助10
13秒前
15秒前
16秒前
坚定小蜜蜂完成签到 ,获得积分10
17秒前
脑洞疼的应助被小涵采纳,获得10
17秒前
乐乐的应助被lkk采纳,获得10
18秒前
Alan睡不醒发布了新的文献求助10
18秒前
王ww完成签到,获得积分10
19秒前
乐空思的应助被吃的薯条采纳,获得30
19秒前
徐开心发布了新的文献求助10
19秒前
22秒前
dundundun完成签到,获得积分10
23秒前
香蕉觅云的应助被didihe采纳,获得10
23秒前
lza发布了新的文献求助10
25秒前
烟花的应助被嘲鸫采纳,获得10
25秒前
25秒前
苏苏苏苏完成签到,获得积分10
26秒前
丘比特的应助被科研通管家采纳,获得10
26秒前
molihuakai的应助被科研通管家采纳,获得10
26秒前
Ava的应助被科研通管家采纳,获得10
26秒前
高分求助中
(应助此贴封号)通过应助OA文献获取积分 10000
Rosenblum, Global Change Biology 800
Organizational Behavior 510
Arbitrage Theory in Discrete and Continuous Time 500
Production Logging: Theoretical and Interpretive Elements 400
English Longitudinal Study of Ageing: Waves 0-11, 1998-2024 300
2026-2030年中國基因檢測行業市場前瞻與未來投資戰略分析報告 300
热门求助领域 (近24小时)
化学 材料科学 医学 生物 计算机科学 工程类 纳米技术 有机化学 化学工程 内科学 物理 生物化学 复合材料 催化作用 细胞生物学 人工智能 心理学 无机化学 基因 遗传学
热门帖子
关注 科研通微信公众号,转发送积分 7827564
求助须知:如何正确求助?哪些是违规求助? 9353121
关于积分的说明 20571235
捐赠科研通 7420520
什么是DOI,文献DOI怎么找? 3335584
关于科研通互助平台的介绍 2480466
邀请新用户注册赠送积分活动 2356044