• Àüü
  • ÀüÀÚ/Àü±â
  • Åë½Å
  • ÄÄÇ»ÅÍ
´Ý±â

»çÀÌÆ®¸Ê

Loading..

Please wait....

±¹³» ³í¹®Áö

Ȩ Ȩ > ¿¬±¸¹®Çå > ±¹³» ³í¹®Áö > Çѱ¹Á¤º¸Ã³¸®ÇÐȸ ³í¹®Áö > Á¤º¸Ã³¸®ÇÐȸ ³í¹®Áö A

Á¤º¸Ã³¸®ÇÐȸ ³í¹®Áö A

Current Result Document :

ÇѱÛÁ¦¸ñ(Korean Title) À¥ ÀÀ¿ë ÇÁ·Î±×·¥ÀÇ ¹®ÀÚ¿­ »ðÀÔ º¸¾È Ãë¾à¼º ºÐ¼®±â °³¹ß
¿µ¹®Á¦¸ñ(English Title) Development of a String Injection Vulnerability Analyzer for Web Application Programs
ÀúÀÚ(Author) ¾ÈÁؼ±   ±è¿µ¹Î   Á¶Àå¿ì   Joonseon Ahn   Yeongmin Kim   Jangwu Jo  
¿ø¹®¼ö·Ïó(Citation) VOL 15-A NO. 03 PP. 0181 ~ 0188 (2008. 06)
Çѱ۳»¿ë
(Korean Abstract)
¿À´Ã³¯ ´ëºÎºÐÀÇ À¥»çÀÌÆ®´Â À¥ ÀÀ¿ë ÇÁ·Î±×·¥ÀÌ ÀûÀýÇÑ À¥ ÆäÀÌÁö¸¦ »ý¼ºÇÏ¿© Àü¼ÛÇÏ´Â ÇüÅÂÀÎ µ¿Àû À¥ÆäÀÌÁö¸¦ »ç¿ëÇÏ°í ÀÖ´Ù. ÀÌ¿¡ ´ëÇÏ¿©, Ãë¾àÇÑ À¥ ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ¾ÇÀÇÀûÀÎ ¹®ÀÚ¿­À» Àü´ÞÇÏ´Â °ø°ÝÀÇ ÇüÅ°¡ Áõ°¡ÇÏ°í ÀÖ´Ù. º» ³í¹®¿¡¼­´Â ´ëÇ¥ÀûÀÎ ¹®ÀÚ¿­ »ðÀÔ °ø°ÝÀÎ SQL »ðÀÔ(SQL Injection) °ø°Ý°ú Å©·Î½º »çÀÌÆ® ½ºÅ©¸³ÆÃ(Cross Site Scripting, XSS) °ø°Ý¿¡ ´ëÇÏ¿© À¥ ÀÀ¿ë ÇÁ·Î±×·¥³»ÀÇ º¸¾È Ãë¾à¼ºÀ» ÀÚµ¿À¸·Î ã¾Æ ÁÖ´Â ÇÁ·Î±×·¥ Á¤Àû ºÐ¼®±â¸¦ °³¹ßÇÏ¿´´Ù. ¿ä¾à Çؼ®À» »ç¿ëÇÑ ÇÁ·Î±×·¥ ºÐ¼®À» À§ÇÏ¿© °¡´ÉÇÑ ¹®ÀÚ¿­ °ªÀ» Á¦¿Ü ¹®ÀÚ¿­µé°ú ÇÔ²² Ç¥ÇöÇÏ´Â ¿ä¾à ÀÚ·á °ø°£°ú PHP ¾ð¾îÀÇ ¿ä¾àµÈ ÀÇ¹Ì ±ÔÄ¢À» ¼³°èÇÏ¿´À¸¸ç, À̸¦ ±â¹ÝÀ¸·Î ºÐ¼®±â¸¦ ±¸ÇöÇÏ¿´´Ù. ¶ÇÇÑ °³¹ßµÈ ºÐ¼®±â°¡ ±âÁ¸ÀÇ ¿¬±¸°á°ú¿Í ºñ±³ÇÏ¿© °æÀï·Â ÀÖ´Â ºÐ¼® ¼Óµµ¿Í Á¤¹Ðµµ¸¦ °¡ÁüÀ» ½ÇÇèÀ» ÅëÇÏ¿© º¸¿´´Ù.
¿µ¹®³»¿ë
(English Abstract)
Nowadays, most web sites are developed using dynamic web pages where web pages are generated and transmitted by web application programs. Therefore, the ratio of attacks injecting malevolent strings to vulnerable web applications is increasing. In this paper, we present a static program analyzer which analyzes whether a web application program has vulnerabilities to the SQL injection attack and the cross site scripting(XSS) attack. To analyze programs using abstract interpretation framework, we designed an abstract domain which models potential string set along with excluded strings and developed an abstract interpreter for the PHP language. Also, based on them, we implemented a static analyzer. According to our experiments, our analyzer has competitive analysis speed and accuracy compared with related research results.
Å°¿öµå(Keyword) Á¤Àû ºÐ¼®   À¥ ÀÀ¿ëÇÁ·Î±×·¥ º¸¾È   SQL »ðÀÔ °ø°Ý   Å©·Î½º »çÀÌÆ® ½ºÅ©¸³Æà °ø°Ý   ¿ä¾à Çؼ®   Static Analysis   Web Application Security   SQL Injection Attack   Cross Site Scripting Attack   Abstract Interpretation  
ÆÄÀÏ÷ºÎ PDF ´Ù¿î·Îµå