亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整的填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

Enhancing Java Web Application Security: Injection Vulnerability Detection via Interprocedural Analysis and Deep Learning

计算机科学 Java 人工智能 程序设计语言 机器学习 情报检索
作者
Bing Zhang,Xuzhe Zhi,Meng Wang,Rong Ren,Jun Dong
出处
期刊:IEEE Transactions on Reliability [Institute of Electrical and Electronics Engineers]
卷期号:: 1-15
标识
DOI:10.1109/tr.2024.3521381
摘要

Injection attacks exploit vulnerabilities in how applications handle user input, allowing malicious code to infiltrate the execution environment of web applications, leading to severe consequences, such as data leaks and system crashes. Traditional dynamic and static detection methods suffer from limitations in manual rule or pattern design and intraprocedural analysis, lacking the capability to automatically learn complex features. Meanwhile, deep learning models encounter challenges, such as feature redundancy and inefficiency, in processing long code sequences. Here, we propose a prototype for detecting I njection V ulnerabilities in Java web applications based on I nterprocedural analysis and the bidirectional encoder representations from transformers B ERT-BiLSTM-CRF model (IVIB), effectively transforming vulnerability detection into text sequence annotation. IVIB employs interprocedural analysis to trace complete program data flow, control flow, method and class dependencies, reducing redundancy through a system dependency graph. Then, we develop intermediate language representation rules and conversion mechanisms specifically for Java programs, symbolically representing code snippets and annotating them to construct a corpus. IVIB achieves remarkable results, with over 96% accuracy, precision, recall, and F1-score in binary classification, surpassing other state-of-the-art models in multiclassification performance. Evaluation on real-world projects demonstrates IVIB's effectiveness, detecting 28 vulnerabilities out of 30 vulnerable slices with low false positives and no false negatives.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
大喵发布了新的文献求助10
刚刚
大喵完成签到,获得积分10
7秒前
17秒前
SCINEXUS完成签到,获得积分0
17秒前
19秒前
TEMPO发布了新的文献求助10
21秒前
sammy关注了科研通微信公众号
22秒前
24秒前
OCDer完成签到,获得积分0
25秒前
陈小子爱梅完成签到,获得积分20
28秒前
35秒前
39秒前
40秒前
Sunny完成签到 ,获得积分10
40秒前
LYL完成签到,获得积分10
42秒前
科研通AI2S应助科研通管家采纳,获得10
44秒前
科研通AI5应助科研通管家采纳,获得10
44秒前
CipherSage应助科研通管家采纳,获得10
44秒前
45秒前
45秒前
45秒前
59秒前
QHX完成签到 ,获得积分10
1分钟前
赵雨轩完成签到 ,获得积分10
1分钟前
精英刺客完成签到 ,获得积分10
1分钟前
SCI的李完成签到 ,获得积分10
1分钟前
Jiaowen完成签到,获得积分10
1分钟前
1分钟前
阿鑫完成签到 ,获得积分10
1分钟前
小二郎应助Sebastian采纳,获得10
2分钟前
2分钟前
李先生完成签到,获得积分10
2分钟前
2分钟前
Lx发布了新的文献求助10
2分钟前
Duan完成签到 ,获得积分10
2分钟前
鹿lu完成签到 ,获得积分10
2分钟前
天天快乐应助科研通管家采纳,获得10
2分钟前
2分钟前
2分钟前
Bin_Liu发布了新的文献求助10
2分钟前
高分求助中
Applied Survey Data Analysis (第三版, 2025) 800
Narcissistic Personality Disorder 700
Assessing and Diagnosing Young Children with Neurodevelopmental Disorders (2nd Edition) 700
The Martian climate revisited: atmosphere and environment of a desert planet 500
Transnational East Asian Studies 400
Towards a spatial history of contemporary art in China 400
Mapping the Stars: Celebrity, Metonymy, and the Networked Politics of Identity 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3845463
求助须知:如何正确求助?哪些是违规求助? 3387759
关于积分的说明 10550463
捐赠科研通 3108399
什么是DOI,文献DOI怎么找? 1712617
邀请新用户注册赠送积分活动 824484
科研通“疑难数据库(出版商)”最低求助积分说明 774843