Detecting application logic vulnerabilities via finding incompatibility between application design and implementation. Issue 4 (1st August 2020)
- Record Type:
- Journal Article
- Title:
- Detecting application logic vulnerabilities via finding incompatibility between application design and implementation. Issue 4 (1st August 2020)
- Main Title:
- Detecting application logic vulnerabilities via finding incompatibility between application design and implementation
- Authors:
- Ghorbanzadeh, Mahmoud
Shahriari, Hamid Reza - Abstract:
- Abstract : Logic vulnerabilities are due to defects in the application logic implementation such that the application logic is not the logic that was expected. Indeed, such vulnerabilities pattern depends on the design and business logic of the application. There are no specific and common patterns for application logic vulnerabilities in commercial applications. In this study, a method named FINAD is introduced to detect application logic vulnerabilities using an activity flow graph (AFG) to find the incompatibilities of an implemented application with its design. In this work, the AFG, consisting of the activity diagram (AD) and control flow graph (CFG), is presented for the first time. Investigation of different common types of application logic vulnerabilities indicated that the majority of such vulnerabilities could be detected through conducting a static analysis on an AFG. The FINAD method is independent of the language and can be used for vulnerability detection for any programming language, provided that the AD is available, and the CFG of the program can be created. Implementation of FINAD for PHP language showed its effectiveness in detecting known logic vulnerabilities in CVE vulnerability database.
- Is Part Of:
- IET software. Volume 14:Issue 4(2020)
- Journal:
- IET software
- Issue:
- Volume 14:Issue 4(2020)
- Issue Display:
- Volume 14, Issue 4 (2020)
- Year:
- 2020
- Volume:
- 14
- Issue:
- 4
- Issue Sort Value:
- 2020-0014-0004-0000
- Page Start:
- 377
- Page End:
- 388
- Publication Date:
- 2020-08-01
- Subjects:
- security of data -- program diagnostics -- flow graphs
application logic vulnerabilities -- business logic -- activity flow graph -- FINAD method -- AFG -- activity diagram -- control flow graph -- CVE vulnerability database
Computer software -- Periodicals
Software engineering -- Periodicals
005.1 - Journal URLs:
- http://digital-library.theiet.org/content/journals/iet-sen ↗
http://ieeexplore.ieee.org/servlet/opac?punumber=4124007 ↗
https://ietresearch.onlinelibrary.wiley.com/journal/17518814 ↗
http://www.theiet.org/ ↗
http://scitation.aip.org/dbt/dbt.jsp?KEY=ISEOB7&Volume=CURVOL&Issue=CURISS ↗ - DOI:
- 10.1049/iet-sen.2019.0186 ↗
- Languages:
- English
- ISSNs:
- 1751-8806
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4363.253550
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 16447.xml