Abstract Parsing: Static analysis of dynamically generated string output
Abstract Parsing: Static analysis of dynamically generated string output
批准号:
0939431
负责人:
David Schmidt
金额:
$29.93万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-08-01 至 2012-07-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
This project provides an automated, formal-methods-based methodology and toolthat analyzes and validates, in advance of its execution,PHP, Perl, or Javascript programs that dynamically generateHMTL, XML, and SQL documents.Such document-generator programs are common to the World Wide Web and arenotorious for generating ill-structured, faulty, and dangerousdocuments that cause subsequent server errors or security breaches.The methodology integrates techniques fromLR(k)-parsing, data-flow analysis, and program securityto synthesize the program-analysis.Given the program (e.g., a PHP script) that generates documents and given thecontext-free reference grammar for the document language(e.g., a grammar for HTML),the analysis tool generates an LR(k) parser for the reference grammarand applies a data-flow analysis to analyze the program andpredict the context-free grammatical structure of thedocuments to be generated by the program.The tool computes abstract parse stacks, a novel and innovative structurethat encodes a generated document's context-free structure.Next, the tool applies formal semantics techniques to compute froman abstract parse stack its context-sensitive semantics, that is, themeaning of the dynamically generated document.Dynamically generated documents are often assembledwith user-supplied input, which can be erroneous or malicious.The analysis annotates the abstract parse stacks to identitywhere user input might appear,and the semantic analysis tracks the influenceof the user input upon the document's meaning.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: Near-Trench Community Geodetic Experiment
-
批准号:2232640
-
项目类别:Continuing Grant
-
资助金额:$82.04万
-
财政年份:2023
-
负责人:David Schmidt
-
依托单位:
Collaborative Research: Constraints on Interseismic Locking near the Trench on the Oregon Segment of the Cascadia Subduction Zone Using Seafloor Geodesy (GNSS-A)
-
批准号:2127140
-
项目类别:Standard Grant
-
资助金额:$27.2万
-
财政年份:2021
-
负责人:David Schmidt
-
依托单位:
GeoPRISMS Synthesis Workshop: The Geological Fingerprints of Slow Earthquakes
-
批准号:2025105
-
项目类别:Standard Grant
-
资助金额:$3.82万
-
财政年份:2020
-
负责人:David Schmidt
-
依托单位:
CoPe RCN: Cascadia Coastal Hazards Research Coordination Network
-
批准号:1940034
-
项目类别:Standard Grant
-
资助金额:$48.62万
-
财政年份:2020
-
负责人:David Schmidt
-
依托单位:
GeoPRISMS Postdoctoral Scholar: Refining GPS-Acoustic Processing to Measure Cascadia Subduction
-
批准号:1850685
-
项目类别:Standard Grant
-
资助金额:$26.03万
-
财政年份:2019
-
负责人:David Schmidt
-
依托单位:
NSFGEO-NERC Collaborative Research: Linking geophysics and volcanic gas measurements to contrain the transcrustal magmatic system at the Altiplano-Puna Deformation Anomaly
-
批准号:1756525
-
项目类别:Standard Grant
-
资助金额:$4.44万
-
财政年份:2018
-
负责人:David Schmidt
-
依托单位:
Collaborative Research: Assessing the State of Locking on the Frontal Thrust of the Cascadia Subduction Zone with Seafloor Geodesy
-
批准号:1658190
-
项目类别:Standard Grant
-
资助金额:$5.06万
-
财政年份:2017
-
负责人:David Schmidt
-
依托单位:
CC*DNI Campus Design: Enhanced Data Delivery at Fort Hays State University
-
批准号:1541394
-
项目类别:Standard Grant
-
资助金额:$35.0万
-
财政年份:2016
-
负责人:David Schmidt
-
依托单位:
Constraints on Slow Slip Behavior in Cascadia Through the Integration of PBO Borehole Strainmeters, GPS Time Series, and Tremor Locations
-
批准号:1251954
-
项目类别:Continuing Grant
-
资助金额:$27.97万
-
财政年份:2013
-
负责人:David Schmidt
-
依托单位:
TWC: Small: Abstract Semantic Processing for Script Security
-
批准号:1219746
-
项目类别:Standard Grant
-
资助金额:$22.69万
-
财政年份:2012
-
负责人:David Schmidt
-
依托单位:
CAREER: Global Assessment of Aseismic Faulting: The Search For a Common Mechanism Among the World's Faults
-
批准号:0548272
-
项目类别:Continuing Grant
-
资助金额:$45.93万
-
财政年份:2006
-
负责人:David Schmidt
-
依托单位:
Optimal Network Geometry for PBO
-
批准号:0346037
-
项目类别:Standard Grant
-
资助金额:$9.0万
-
财政年份:2004
-
负责人:David Schmidt
-
依托单位:
SGER: Direct Numerical Simulation of Turbulent Drop Dispersion
-
批准号:0332446
-
项目类别:Standard Grant
-
资助金额:$9.96万
-
财政年份:2003
-
负责人:David Schmidt
-
依托单位:
U.S.-Germany Cooperative Research: Integrating Platforms for Finite-State Verification
-
批准号:9981558
-
项目类别:Standard Grant
-
资助金额:$1.55万
-
财政年份:2000
-
负责人:David Schmidt
-
依托单位:
Static Analysis Based on Model Checking
-
批准号:9970679
-
项目类别:Standard Grant
-
资助金额:$10.5万
-
财政年份:1999
-
负责人:David Schmidt
-
依托单位:
Logical Support for High-Assurance Software Evolution
-
批准号:9633388
-
项目类别:Continuing Grant
-
资助金额:$20.0万
-
财政年份:1996
-
负责人:David Schmidt
-
依托单位:
Analysis and Classification of Programming Languages
-
批准号:9302962
-
项目类别:Continuing Grant
-
资助金额:$22.1万
-
财政年份:1993
-
负责人:David Schmidt
-
依托单位:
US-France (INRIA) Cooperative Research: Semantics Driven Compiler Synthesis
-
批准号:9014042
-
项目类别:Standard Grant
-
资助金额:$1.46万
-
财政年份:1991
-
负责人:David Schmidt
-
依托单位:
Action Semantics and Partial Evaluation
-
批准号:9102625
-
项目类别:Continuing Grant
-
资助金额:$15.74万
-
财政年份:1991
-
负责人:David Schmidt
-
依托单位:
Semantics-Driven Compiler Synthesis
-
批准号:8822378
-
项目类别:Standard Grant
-
资助金额:$15.73万
-
财政年份:1989
-
负责人:David Schmidt
-
依托单位:
海外基金