Paper published in a book (Scientific congresses, symposiums and conference proceedings)
KAVe: A Tool to Detect XSS and SQLi Vulnerabilities using a Multi-Agent System over a Multi-Layer Knowledge Graph
ROSA MESQUITA RAMIRES, Rafael Francisco; PAPADAKIS, Michail; Respício, Ana et al.
2025In Li, Jingyue (Ed.) FSE Companion 2025 - Companion Proceedings of the 33rd ACM International Conference on the Foundations of Software Engineering
Peer reviewed
 

Files


Full Text
3696630.3728601.pdf
Publisher postprint (699.2 kB) Creative Commons License - Attribution
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Multi-Agent System; Multi-Layer Knowledge Graph; Software Security; Static Analysis; Web Application Vulnerabilities; Application developers; Knowledge graphs; Multi-layer knowledge graph; Multi-layers; Multiagent systems (MASs); Software security; SQL injection; WEB application; Web application vulnerability; Web applications; Software
Abstract :
[en] Web applications have been widely adopted to access a myriad of services, regardless of their criticality and context. Applications developers have accelerated their efforts to meet the demands of a competitive and dynamic market for innovative products. Despite considerable efforts to detect and mitigate vulnerabilities in applications, their prevalence continues to increase, primarily due to the rapid pace of software development, which often prioritizes deployment speed, compromising security. This paper presents KAVe, a static analysis tool that leverages a multi-layer knowledge graph and a multi-agent system to detect web application vulnerabilities with high precision. This paper showcases KAVe’s implementation and ability to identify SQL injection (SQLi) and cross-site scripting (XSS) vulnerabilities in real-world PHP applications.
Disciplines :
Computer science
Author, co-author :
ROSA MESQUITA RAMIRES, Rafael Francisco  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SerVal ; LASIGE, DI, Faculdade de Ciências, Universidade de Lisboa, Portugal
PAPADAKIS, Michail  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SerVal
Respício, Ana ;  LASIGE, DI, Faculdade de Ciências, Universidade de Lisboa, Portugal
Medeiros, Ibéria ;  LASIGE, DI, Faculdade de Ciências, Universidade de Lisboa, Portugal
External co-authors :
yes
Language :
English
Title :
KAVe: A Tool to Detect XSS and SQLi Vulnerabilities using a Multi-Agent System over a Multi-Layer Knowledge Graph
Publication date :
28 July 2025
Event name :
Proceedings of the 33rd ACM International Conference on the Foundations of Software Engineering
Event place :
Trondheim, Nor
Event date :
23-06-2025 => 27-06-2025
Main work title :
FSE Companion 2025 - Companion Proceedings of the 33rd ACM International Conference on the Foundations of Software Engineering
Editor :
Li, Jingyue
Publisher :
Association for Computing Machinery
ISBN/EAN :
9798400712760
Peer reviewed :
Peer reviewed
Funders :
ACM SIGSOFT
ByteDance
et al.
Huawei
Research Council of Norway
U.S. National Science Foundation
Funding text :
This work was partially supported by P2030 through project I2DT, ref. COMPETE2030-FEDER-00389100, an ITEA4 European project (ref. 22025), and by FCT through the LASIGE Research Unit, ref. UIDB/00408/2025-LASIGE.
Available on ORBilu :
since 22 October 2025

Statistics


Number of views
44 (3 by Unilu)
Number of downloads
10 (0 by Unilu)

Scopus citations®
 
0
Scopus citations®
without self-citations
0
OpenCitations
 
0
OpenAlex citations
 
0

Bibliography


Similar publications



Contact ORBilu