Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
JoanAudit: A Tool for Auditing Common Injection Vulnerabilities
THOME, Julian; SHAR, Lwin Khin; BIANCULLI, Domenico et al.
2017In 11th Joint Meeting of the European Software Engineering Conference and the ACM SIGSOFT Symposium on the Foundations of Software Engineering
Peer reviewed
 

Documents


Texte intégral
esec-fse2017-demo.pdf
Preprint Auteur (644.86 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Security Auditing; Static Analysis; Vulnerability; Automated Code Fixing
Résumé :
[en] JoanAudit is a static analysis tool to assist security auditors in auditing Web applications and Web services for common injection vulnerabilities during software development. It automatically identifies parts of the program code that are relevant for security and generates an HTML report to guide security auditors audit the source code in a scalable way. JoanAudit is configured with various security-sensitive input sources and sinks relevant to injection vulnerabilities and standard sanitization procedures that prevent these vulnerabilities. It can also automatically fix some cases of vulnerabilities in source code — cases where inputs are directly used in sinks without any form of sanitization — by using standard sanitization procedures. Our evaluation shows that by using JoanAudit, security auditors are required to inspect only 1% of the total code for auditing common injection vulnerabilities. The screen-cast demo is available at https://github.com/julianthome/joanaudit.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Software Verification and Validation Lab (SVV Lab)
Disciplines :
Sciences informatiques
Auteur, co-auteur :
THOME, Julian ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
SHAR, Lwin Khin ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
BIANCULLI, Domenico  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
BRIAND, Lionel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Co-auteurs externes :
no
Langue du document :
Anglais
Titre :
JoanAudit: A Tool for Auditing Common Injection Vulnerabilities
Date de publication/diffusion :
septembre 2017
Nom de la manifestation :
ESEC/FSE 2017: 11th Joint Meeting of the European Software Engineering Conference and the ACM SIGSOFT Symposium on the Foundations of Software Engineering
Lieu de la manifestation :
Paderborn, Allemagne
Date de la manifestation :
from 04-09-2017 to 08-09-2017
Manifestation à portée :
International
Titre de l'ouvrage principal :
11th Joint Meeting of the European Software Engineering Conference and the ACM SIGSOFT Symposium on the Foundations of Software Engineering
Maison d'édition :
ACM
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Projet FnR :
FNR9132112 - A Scalable And Accurate Hybrid Vulnerability Analysis Framework, 2014 (01/09/2014-14/04/2018) - Julian Thomé
Organisme subsidiant :
FNR - Fonds National de la Recherche
Disponible sur ORBilu :
depuis le 11 juillet 2017

Statistiques


Nombre de vues
478 (dont 45 Unilu)
Nombre de téléchargements
879 (dont 26 Unilu)

citations Scopus®
 
10
citations Scopus®
sans auto-citations
10
OpenCitations
 
6
citations OpenAlex
 
11

Bibliographie


Publications similaires



Contacter ORBilu