已入深夜,您辛苦了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!祝你早点完成任务,早点休息,好梦!

Enhancing Java Web Application Security: Injection Vulnerability Detection via Interprocedural Analysis and Deep Learning

计算机科学 Java 人工智能 程序设计语言 机器学习 情报检索
作者
Bing Zhang,Xuzhe Zhi,Meng Wang,Rong Ren,Jun Dong
出处
期刊:IEEE Transactions on Reliability [Institute of Electrical and Electronics Engineers]
卷期号:: 1-15
标识
DOI:10.1109/tr.2024.3521381
摘要

Injection attacks exploit vulnerabilities in how applications handle user input, allowing malicious code to infiltrate the execution environment of web applications, leading to severe consequences, such as data leaks and system crashes. Traditional dynamic and static detection methods suffer from limitations in manual rule or pattern design and intraprocedural analysis, lacking the capability to automatically learn complex features. Meanwhile, deep learning models encounter challenges, such as feature redundancy and inefficiency, in processing long code sequences. Here, we propose a prototype for detecting I njection V ulnerabilities in Java web applications based on I nterprocedural analysis and the bidirectional encoder representations from transformers B ERT-BiLSTM-CRF model (IVIB), effectively transforming vulnerability detection into text sequence annotation. IVIB employs interprocedural analysis to trace complete program data flow, control flow, method and class dependencies, reducing redundancy through a system dependency graph. Then, we develop intermediate language representation rules and conversion mechanisms specifically for Java programs, symbolically representing code snippets and annotating them to construct a corpus. IVIB achieves remarkable results, with over 96% accuracy, precision, recall, and F1-score in binary classification, surpassing other state-of-the-art models in multiclassification performance. Evaluation on real-world projects demonstrates IVIB's effectiveness, detecting 28 vulnerabilities out of 30 vulnerable slices with low false positives and no false negatives.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
白茶完成签到 ,获得积分10
刚刚
刚刚
1秒前
doctor_lin发布了新的文献求助10
1秒前
2秒前
PingxuZhang发布了新的文献求助10
3秒前
Kivaria完成签到,获得积分10
3秒前
August关注了科研通微信公众号
4秒前
5秒前
科研通AI6.1应助整齐摩托采纳,获得10
5秒前
8秒前
8秒前
8秒前
英姑应助doctor_lin采纳,获得10
9秒前
CipherSage应助机智友蕊采纳,获得10
10秒前
13秒前
大模型应助杨大泡泡采纳,获得10
16秒前
xyx关注了科研通微信公众号
17秒前
17秒前
18秒前
liuheqian发布了新的文献求助10
18秒前
烟花应助张泽升采纳,获得10
19秒前
王讯发布了新的文献求助10
19秒前
西西弗斯完成签到,获得积分0
21秒前
无花果应助liuheqian采纳,获得10
23秒前
23秒前
吾问无为谓完成签到,获得积分10
24秒前
26秒前
27秒前
在水一方应助雪轩采纳,获得10
27秒前
朱子菱发布了新的文献求助10
29秒前
芳芳芳芳发布了新的文献求助10
31秒前
31秒前
自然丹寒发布了新的文献求助10
32秒前
泡泡发布了新的文献求助20
34秒前
玩家X完成签到 ,获得积分10
36秒前
pppp完成签到,获得积分10
38秒前
39秒前
41秒前
41秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
APA handbook of humanistic and existential psychology: Clinical and social applications (Vol. 2) 2000
Cronologia da história de Macau 1600
Handbook on Climate Mobility 1111
Lloyd's Register of Shipping's Approach to the Control of Incidents of Brittle Fracture in Ship Structures 1000
BRITTLE FRACTURE IN WELDED SHIPS 1000
Intentional optical interference with precision weapons (in Russian) Преднамеренные оптические помехи высокоточному оружию 1000
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 纳米技术 计算机科学 化学工程 生物化学 物理 复合材料 内科学 催化作用 物理化学 光电子学 细胞生物学 基因 电极 遗传学
热门帖子
关注 科研通微信公众号,转发送积分 6176314
求助须知:如何正确求助?哪些是违规求助? 8004020
关于积分的说明 16647855
捐赠科研通 5279490
什么是DOI,文献DOI怎么找? 2815197
邀请新用户注册赠送积分活动 1794958
关于科研通互助平台的介绍 1660254