首页    期刊浏览 2025年09月17日 星期三
登录注册

文章基本信息

  • 标题:Automated server-side model for recognition of security vulnerabilities in scripting languages
  • 本地全文:下载
  • 作者:Rabab F. Abdel-Kader ; Mona Nashaat ; Mohamed I. Habib
  • 期刊名称:International Journal of Electrical and Computer Engineering
  • 电子版ISSN:2088-8708
  • 出版年度:2020
  • 卷号:10
  • 期号:6
  • 页码:6061-6070
  • DOI:10.11591/ijece.v10i6.pp6061-6070
  • 出版社:Institute of Advanced Engineering and Science (IAES)
  • 摘要:With the increase of global accessibility of web applications, maintaining a reasonable security level for both user data and server resources has become an extremely challenging issue. Therefore, static code analysis systems can help web developers to reduce time and cost. In this paper, a new static analysis model is proposed. This model is designed to discover the security problems in scripting languages. The proposed model is implemented in a prototype SCAT, which is a static code analysis Tool. SCAT applies the phases of the proposed model to catch security vulnerabilities in PHP 5.3. Empirical results attest that the proposed prototype is feasible and is able to contribute to the security of real-world web applications. SCAT managed to detect 94% of security vulnerabilities found in the testing benchmarks; this clearly indicates that the proposed model is able to provide an effective solution to complicated web systems by offering benefits of securing private data for users and maintaining web application stability for web applications providers.
  • 关键词:Data flow computing;Data security;Object-oriented programming;Software protection;Software testing
国家哲学社会科学文献中心版权所有