Static and dynamic analysis for web security in industry applications

被引:2
作者
Wu, Raymond [1 ]
Hisada, Masayuki [1 ]
机构
[1] NST Inc, Dept Res & Dev, Aizu Wakamatsu, Fukushima, Japan
关键词
vulnerability; web security; static analysis; dynamic analysis; tracking; abstract syntax;
D O I
10.1504/IJESDF.2010.033782
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
To apply our analysis work in industry security applications, we are investigating semantic metadata and structural syntax analysis. This paper explains how our approaches achieve the goal in terms of static and dynamic analysis by using industry scenarios. To better explain the framework and roadmap, we describe our approaches by using macro and micro views individually. Macro view oversees syntax structure and identification, while micro view envisions metadata messaging and parser automaton. The coherence of macro and micro views forms web security framework in tracking and validation. Our research applies the security service in industry fraud detection. It demonstrates metadata messaging for tracking, and HIPA code generation for validation. This bridges the gap between static and dynamic analysis. This also builds up the foundation of web security governance.
引用
收藏
页码:138 / 150
页数:13
相关论文
共 13 条
[1]  
Anley C, 2002, ADV SQL INJECTION SQ
[2]  
Christensen A., 2003, P 10 STAT AN S
[3]  
GEGICK M, 2007, 1 INT WORKSH SYST VU
[4]  
GOULD C, 2004, P 26 INT C SOFTW ENG
[5]  
Liu A., 2009, SAC
[6]  
Livshits Benjamin, 2006, THESIS
[7]  
Livshits VB, 2005, USENIX ASSOCIATION PROCEEDINGS OF THE 14TH USENIX SECURITY SYMPOSIUM, P271
[8]  
PIETRASZEK T, 2005, RECENT ADV INTRUSION
[9]  
Pietraszekl T., 2004, DEFENDING INJECTION
[10]  
Wu R., 2007, INT J INFORM SYSTEMS, V2