ANOVUL: Detection of logic vulnerabilities in annotated programs via data and control flow analysis. (1st May 2020)
- Record Type:
- Journal Article
- Title:
- ANOVUL: Detection of logic vulnerabilities in annotated programs via data and control flow analysis. (1st May 2020)
- Main Title:
- ANOVUL: Detection of logic vulnerabilities in annotated programs via data and control flow analysis
- Authors:
- Ghorbanzadeh, Mahmoud
Reza Shahriari, Hamid - Abstract:
- Abstract : Logic vulnerabilities are largely dependent on the expected functions of web applications. Their appearance depends on both application logic and related security policy which may change based on modifications in business requirements. Accordingly, there are no specific and common patterns for logic vulnerabilities moreover, a security policy is required for their detection. In this study, a vulnerability detection method is proposed to detect logic vulnerabilities via analysing the program source code. Security checks enforce some constraints in the application so that the application behaves according to the logic intended by the programmer. The main goal is to find the vulnerabilities caused by bypassing some security checks. In this method, known as annotation‐based vulnerability detection approach (ANOVUL), control and data flows are analysed to detect the application logic vulnerabilities. To analyse the flows of the program, access control and authenticity labelling are used. To evaluate ANOVUL, the authors have collected a data set. This comprises of PHP applications with reported logic vulnerabilities that have common vulnerabilities and exposures (CVE) identifiers. Based on the results, a 73% detection rate was achieved in the data set. The proposed method can detect logic vulnerabilities that are not detectable using conventional methods.
- Is Part Of:
- IET information security. Volume 14:Number 3(2020)
- Journal:
- IET information security
- Issue:
- Volume 14:Number 3(2020)
- Issue Display:
- Volume 14, Issue 3 (2020)
- Year:
- 2020
- Volume:
- 14
- Issue:
- 3
- Issue Sort Value:
- 2020-0014-0003-0000
- Page Start:
- 352
- Page End:
- 364
- Publication Date:
- 2020-05-01
- Subjects:
- authorisation -- Internet -- data flow analysis
ANOVUL -- control flow analysis -- related security policy -- vulnerability detection method -- security checks -- application logic vulnerabilities -- common vulnerabilities -- logic vulnerabilities detection -- annotation‐based vulnerability detection approach
Computer security -- Periodicals
Cryptography -- Periodicals
Computer networks -- Security measures -- Periodicals
Database security -- Periodicals
005.8 - Journal URLs:
- https://ietresearch.onlinelibrary.wiley.com/journal/17518717 ↗
http://digital-library.theiet.org/content/journals/iet-ifs ↗
http://www.ietdl.org/IET-IFS ↗
http://www.theiet.org/ ↗ - DOI:
- 10.1049/iet-ifs.2018.5615 ↗
- Languages:
- English
- ISSNs:
- 1751-8709
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4363.252660
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 16470.xml