Framework for Static Analysis of PHP Applications

Framework for Static Analysis of PHP Applications
复制标题

PHP 应用程序静态分析框架

DOI:
10.4230/lipics.ecoop.2015.689
复制
发表时间:
2015
期刊:
2009 IEEE 31st International Conference on Software Engineering
影响因子:
--
通讯作者:
J. Kofroň
J. Kofroň
中科院分区:
--
文献类型:
--
作者:
David Hauzar;J. Kofroň

文献摘要

被引文献

相似文献

动态语言,例如 PHP 和 JavaScript,被广泛使用并被大量使用。它们提供动态功能,例如动态类型系统、虚拟和动态方法调用、动态包含和内置动态数据结构。这使得创建静态分析(例如自动发现错误)变得困难。然而,利用此类程序中的错误,尤其是 Web 应用程序中的错误,可能会产生重大影响。在本文中,我们提出了 PHP 静态分析框架,自动解析动态语言常见的功能,从而降低定义新静态分析的复杂性。特别是,该框架能够独立地定义动态语言的值和堆分析,并自动、合理地组合它们。我们使用该框架来实现静态污点分析以查找安全漏洞。分析揭示了实际应用中以前未知的安全问题。与现有最先进的 PHP 分析工具相比,它发现了更多真实问题,误报率更低。
Dynamic languages, such as PHP and JavaScript, are widespread and heavily used. They provide dynamic features such as dynamic type system, virtual and dynamic method calls, dynamic includes, and built-in dynamic data structures. This makes it hard to create static analyses, e.g., for automatic error discovery. Yet exploiting errors in such programs, especially in web applications, can have significant impacts. In this paper, we present static analysis framework for PHP, automatically resolving features common to dynamic languages and thus reducing the complexity of defining new static analyses. In particular, the framework enables defining value and heap analyses for dynamic languages independently and composing them automatically and soundly. We used the framework to implement static taint analysis for finding security vulnerabilities. The analysis has revealed previously unknown security problems in real application. Comparing to existing state-of-the-art analysis tools for PHP, it has found more real problems with a lower false-positive rate.