课题基金 / 基金详情

TC: Small: Collaborative Research: Viewpoints: Discovering Client- and Server-side Input Validation Inconsistencies to Improve Web Application Security

TC: Small: Collaborative Research: Viewpoints: Discovering Client- and Server-side Input Validation Inconsistencies to Improve Web Application Security
TC:小型:协作研究:观点:发现客户端和服务器端输入验证不一致以提高 Web 应用程序安全性
批准号:
1117167
负责人:
Alessandro Orso
金额:
$20.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-10-01 至 2014-09-30

项目摘要

项目成果

Alessandro Orso的其他基金

相似基金

相关文献

中文摘要
翻译
Web应用程序在社会的许多方面都越来越重要,从社交互动到商业交易。因此,Web应用程序的安全性是一个非常重要和紧迫的问题。 由于Web应用程序易于访问,并且通常存储大量敏感的用户信息,因此它们是攻击者的典型目标。特别是,针对输入验证漏洞的攻击非常常见和有效。其中一些攻击利用众所周知的漏洞,如跨站点脚本和SQL注入,而另一些攻击则利用难以识别的应用程序特定漏洞,因为它们依赖于目标应用程序的特定输入验证逻辑。一般来说,这些攻击利用错误或不充分的输入验证和消毒注入恶意数据,可能会导致有害的命令执行和访问敏感信息。本研究旨在识别和减轻这些漏洞的Web应用程序执行输入验证和消毒操作的自动检查。这项工作的关键见解来自于开发人员经常在Web应用程序的前端(客户端)和后端(服务器)组件中引入冗余检查的观察。 客户端检查速度很快,可以提高应用程序的性能和响应能力,但很容易被规避;服务器端检查很难规避,但需要网络往返和额外的服务器端处理。 我们的直觉是,在客户端和服务器端执行的检查应该对输入执行相同的约束:如果客户端检查更具限制性,服务器可能会接受合法客户端永远无法产生的输入,因为恶意用户可以轻松绕过客户端检查。相反,如果服务器端检查的限制性更强,客户端可能会产生随后被服务器拒绝的请求,从性能的角度来看,这并不理想。这项研究将开发基于程序分析,字符串分析和代码合成的新技术,可以识别,映射,建模和比较在客户端和服务器端执行的检查集。这些技术将能够识别和报告两组检查之间的不一致,并(半)自动扩展检查以消除这种不一致。 通过使Web应用程序更加安全和高效,这项研究有可能使越来越多的依赖于使用Web应用程序进行日常活动的社会受益。
英文摘要
Web applications are an increasingly important part of many aspects of the society, from social interactions to business transactions. Hence, security of web applications is an extremely important and urgent problem. Since web applications are easily accessible, and often store a large amount of sensitive user information, they are a typical target for attackers. In particular, attacks that target input validation vulnerabilities are extremely common and effective. Some of these attacks exploit well-known vulnerabilities, such as cross-site scripting and SQL injection, whereas some others exploit application-specific vulnerabilities that are hard to identify because they depend on the particular input validation logic of the target application. In general, these attacks exploit erroneous or insufficient input validation and sanitization to inject malicious data that can result in execution of harmful commands and access to sensitive information.This research aims to identify and mitigate these vulnerabilities in web applications by performing automatic checking of input validation and sanitization operations. The key insight for this work comes from the observation that developers often introduce redundant checks in both the front-end (client) and the back-end (server) component of a web application. Client-side checks are fast and can improve performance and responsiveness of the application, but can be easily circumvented; server-side checks are hard to circumvent, but require network round-trips and additional server-side processing. Our intuition is that the checks performed at the client and server sides should enforce the same set of constraints on the inputs: if client-side checks are more restrictive, the server may accept inputs that legitimate clients can never produce, as malicious users can easily bypass client-side checks. Conversely, if server-side checks are more restrictive, the client may produce requests that are subsequently rejected by the server, which is not ideal from a performance point of view. This research will develop new techniques based on program analysis, string analysis, and code synthesis that can identify, map, model, and compare the set of checks performed on the client and server sides. These techniques will be able to identify and report inconsistencies between the two sets of checks and (semi)automatically extend the checks to eliminate such inconsistencies. By making web applications more secure and efficient, this research has the potential to benefit the increasingly large part of the society that relies on the use of web applications for its daily activities.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SHF: Medium: A General Framework for Automated Test Transfer
  • 批准号:
    2107125
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2021
  • 负责人:
    Alessandro Orso
  • 依托单位:
SHF: Medium: Spectral Profiling: Understanding Software Performance without Code Instrumentation
  • 批准号:
    1563991
  • 项目类别:
    Standard Grant
  • 资助金额:
    $85.0万
  • 财政年份:
    2016
  • 负责人:
    Alessandro Orso
  • 依托单位:
EAGER: Collaborative Research: Leveraging Graph Databases for Incremental and Scalable Symbolic Analysis and Verification of Web Applications
  • 批准号:
    1548856
  • 项目类别:
    Standard Grant
  • 资助金额:
    $10.0万
  • 财政年份:
    2015
  • 负责人:
    Alessandro Orso
  • 依托单位:
I-Corps: Capturing Field Data for Mobile Applications
  • 批准号:
    1522518
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2015
  • 负责人:
    Alessandro Orso
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: