• Home
  • Search
  • Research on Vulnerability Detection for Software Based on Taint Analysis
  • Open Access IconOpen Access
  • https://doi.org/10.4028/www.scientific.net/amm.347-350.3715Copy DOI Icon

Research on Vulnerability Detection for Software Based on Taint Analysis

Show More
  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

At present, Cross Site Scripting (XSS) vulnerability exists in most web sites. The main reason is the lack of effective validation and filtering mechanisms for user input data from web request. This paper explores vulnerability detection method which based on taint dependence analysis and implements a prototype system for Java Web program. We treat all user input as tainted data, and track the flow of Web applications, then we judge whether it will trigger an attack or not. The taint dependent analysis algorithm mentioned in this paper is used to construct the taint dependency graph. Next the value representation method of the string tainted object based on finite state automata is discussed. Finally, we propose the vulnerability detection method for the program. The experiment result shows that the prototype system can detect reflection cross-site scripting vulnerability well in those programs which dont have effective treatment for the user input data.

Similar Papers
  • Conference Article
  • Citations1

Detection and Defense of XSS Attack Script Based on Machine Learning

  • Aug 18, 2023
  • Huanxi Zhao +1
  • Conference Article
  • Citations11

Design of automatic vulnerability detection system for Web application program

  • May 01, 2013
  • Binbin Qu +3
  • Conference Article
  • Citations19

Reducing attack surface corresponding to Type 1 cross-site scripting attacks using secure development life cycle practices

  • Feb 01, 2018
  • Syed Nisar Bukhari +2
  • Research Article
  • Citations15

Vulnerability detection through cross-modal feature enhancement and fusion

  • Jun 18, 2023
  • Computers & Security
  • Wenxin Tao +4
  • Research Article
  • Citations9

BinAIV: Semantic-enhanced vulnerability detection for Linux x86 binaries

  • Sep 27, 2023
  • Computers & Security
  • Yeming Gu +2
  • Conference Article
  • Citations21

Cross-program taint analysis for IoT systems

  • Mar 30, 2020
  • Amit Mandal +4
  • PDF
  • Research Article
  • Citations5

Learning and Fusing Multi-View Code Representations for Function Vulnerability Detection

  • Jun 01, 2023
  • Electronics
  • Zhenzhou Tian +3
  • PDF
  • Research Article
  • Citations81

Automated Vulnerability Detection in Source Code Using Minimum Intermediate Representation Learning

  • Mar 02, 2020
  • Applied Sciences
  • Xin Li +4
  • Conference Article
  • Citations9

Performance Comparison on SQL Injection and XSS Detection using Open Source Vulnerability Scanners

  • Oct 06, 2021
  • Busra Zukran +1
  • Research Article
  • Citations5

Source Code Vulnerability Detection Based on Joint Graph and Multimodal Feature Fusion

  • Feb 28, 2025
  • Electronics
  • Dun Jin +4
  • PDF
  • Research Article
  • Citations9

Grey-Box Fuzzing Based on Reinforcement Learning for XSS Vulnerabilities

  • Feb 15, 2023
  • Applied Sciences
  • Xuyan Song +3
  • PDF
  • Research Article
  • Citations4

Models and scenarios of implementation of threats for internet resources

  • Dec 18, 2020
  • Russian Technological Journal
  • S A Lesko
  • PDF
  • Research Article
  • Citations4

IRC-CLVul: Cross-Programming-Language Vulnerability Detection with Intermediate Representations and Combined Features

  • Jul 13, 2023
  • Electronics
  • Tianwei Lei +3
  • Research Article

CERT issues ‘cross-site scripting’ warning

  • Apr 01, 2000
  • Computer Fraud & Security
  • Barbara Gengler
  • Research Article
  • Citations1

Research on Java Source Code Static Analysis Based on Taint Tracking

  • Aug 11, 2014
  • Applied Mechanics and Materials
  • Li Fang Han +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.