|国家预印本平台
首页|基于静态分析的Web身份认证缺陷的检测方法研究

基于静态分析的Web身份认证缺陷的检测方法研究

Research on Detection Method of Web Identity Authentication Defects Based on Static Analysis

中文摘要英文摘要

Web应用程序作为一项发展快速且高度普及的技术,它覆盖了我们工作和生活的各个方面。身份认证作为Web应用程序非常重要的一道防线,它保护着用户的隐私和财产安全,但是随着Web应用程序的应用范围飞速扩大,在复杂多变的互联网环境下,身份认证缺陷让Web系统变得更加脆弱,因此需要方法来前置发现这类缺陷。本文提出身份认证缺陷数据流分析检测算法来检测Web应用中的身份认证缺陷,并提出运行时特性解析算法,解决了三类运行时特性导致的调用链路缺失问题,提高了Web应用身份认证缺陷静态检测的精度。实验结果表明身份认证缺陷数据流分析检测算法相较于Soot能够在分析时间不发生劣化的情况下准确识别存在缺陷的调用链路,在实验数据中检测结果实现零误报,证明本文方法的有效性。

s a rapidly developing and highly popular technology, Web applications cover all aspects of our work and life. As a very important line of defense for Web applications, identity authentication protects users\' privacy and property security. However, with the rapid expansion of the application scope of Web applications, in the complex and volatile Internet environment, identity authentication defects make Web systems more vulnerable. Therefore, methods are needed to detect such defects in advance. This paper proposes an identity authentication flaw data flow analysis detection algorithm to detect identity authentication flaws in Web applications, and proposes a run-time feature analysis algorithm to solve the problem of missing call links caused by three types of run-time features, improving the accuracy of static detection of identity authentication flaws in Web applications. The experimental results show that the identity authentication defect data flow analysis and detection algorithm can accurately identify the defective call link without deterioration of the analysis time, and the detection results in the experimental data achieve zero false positives, which proves the effectiveness of the method in this paper.

涂腾飞、蒋发群、吕腾飞

计算技术、计算机技术

Web安全静态分析运行时特性解析身份认证缺陷检测

Network SecurityStatic AnalysisRuntime Feature Analysisuthentication Flaw Detection

涂腾飞,蒋发群,吕腾飞.基于静态分析的Web身份认证缺陷的检测方法研究[EB/OL].(2023-02-08)[2025-08-16].http://www.paper.edu.cn/releasepaper/content/202302-44.点此复制

评论