Static approximation of dynamically generated Web pages

Static approximation of dynamically generated Web pages
复制标题

DOI:
10.1145/1060745.1060809
复制
发表时间:
2005-05
期刊:
--
影响因子:
--
通讯作者:
Yasuhiko Minamide
Yasuhiko Minamide
中科院分区:
其他
文献类型:
--
作者:
Yasuhiko Minamide

文献摘要

被引文献

相似文献

服务器端编程是支持当今WWW环境的关键技术之一。它可以根据用户的请求动态生成Web页面,并为每个用户定制页面。然而,通过服务器端编程获得的灵活性使得保证动态生成页面的有效性和安全性变得更加困难。为了静态地检查由服务器端程序动态生成的Web页面的属性,我们开发了一个静态程序分析,它用上下文无关的语法近似程序的字符串输出。分析器获得的近似值可用于检查服务器端程序及其生成的页面的各种属性。为了演示分析的有效性,我们为服务器端脚本语言PHP实现了一个字符串分析器。分析器成功地应用于公开可用的PHP程序,以检测跨站点脚本漏洞并验证它们动态生成的页面。
Server-side programming is one of the key technologies that support today's WWW environment. It makes it possible to generate Web pages dynamically according to a user's request and to customize pages for each user. However, the flexibility obtained by server-side programming makes it much harder to guarantee validity and security of dynamically generated pages.To check statically the properties of Web pages generated dynamically by a server-side program, we develop a static program analysis that approximates the string output of a program with a context-free grammar. The approximation obtained by the analyzer can be used to check various properties of a server-side program and the pages it generates.To demonstrate the effectiveness of the analysis, we have implemented a string analyzer for the server-side scripting language PHP. The analyzer is successfully applied to publicly available PHP programs to detect cross-site scripting vulnerabilities and to validate pages they generate dynamically.