Title :
Notice of Retraction
A Static Analysis Tool for Detecting Web Application Injection Vulnerabilities for ASP Program
Author :
Xin-hua Zhang ; Zhi-jian Wang
Author_Institution :
Comput. & Inf. Eng. Coll., Hohai Univ., Nanjing, China
Abstract :
Notice of Retraction
After careful and considered review of the content of this paper by a duly constituted expert committee, this paper has been found to be in violation of IEEE´s Publication Principles.
We hereby retract the content of this paper. Reasonable effort should be made to remove all past references to this paper.
The presenting author of this paper has the option to appeal this decision by contacting TPII@ieee.org.
Publicly reported vulnerability in recent years strong growth of the Web Application , Cross-site scripting (XSS) and SQL injection have been the most dominant class of web vulnerabilities, Web application security has been a great challenge. For the case, the static analysis tools ASPWC presented in this paper to detect XSS attacks and SQL injection vulnerabilities based on taint analysis, It tracks various kinds of external input, tags taint types, constructing control flow graph is constructed based on the use of data flow analysis of the relevant information, taint data propagate to various kinds of vulnerability functions, and detect the XSS or SQL Injection vulnerability in web application´s source code. Experiments show that the detection approach is an effective way; it can be used to detect the XSS and SQL Injection vulnerability in the web application program based on ASP technology development.
Keywords :
SQL; authoring languages; data flow analysis; ASP program; SQL injection; Web application injection vulnerabilities; control flow graph; cross site scripting; data flow analysis; static analysis tool; Application software; Application specific processors; Computer security; Databases; Educational institutions; Flow graphs; Information analysis; Information security; Software design; Software testing;
Conference_Titel :
e-Business and Information System Security (EBISS), 2010 2nd International Conference on
Conference_Location :
Wuhan
Print_ISBN :
978-1-4244-5893-6
DOI :
10.1109/EBISS.2010.5473561