题名

字串限制式在行動應用程式安全檢測的應用

作者

陳郁方

关键词

字串限制式 ; 行動應用程式 ; HTML ; 注入式攻擊

期刊名称

資訊安全通訊

卷期/出版年月

21卷2期(2015 / 04 / 01)

页次

60 - 66

内容语文

繁體中文

中文摘要

根據OWASP統計,近年來注入式攻擊(injection attack),在網頁程式和行動應用程式都是排名前十的攻擊方式。這類攻擊的原理,是攻擊者利用程式對於各種輸入來源沒有詳盡過濾的漏洞,藉機輸入程式原先設計外的可執行程式字串。執行這樣的字串,有可能造成各式各樣的損失。輕則遺失資料或系統損毀,重者甚至會泄露極重要的個人隱私資料。字串限制式的解答技術,針對這樣的攻擊,可以有效率地找出潛在的漏洞並加以防治。我們相信是個很有潛力的新興方法。本文將對這個主題進行一個介紹性的探討。

主题分类 基礎與應用科學 > 資訊科學
参考文献
  1. http://www.eweek.com/c/a/Application-Development/75-of-Developers-Using-HTML5-Survey-508096
  2. https://www.owasp.org/index.php/OWASP_Mobile_Security_Project#tab=Top_10_Mobile_Risks.
  3. Abdulla, P. A.,Atig, M. F.,Chen, Y. F.,Holík, L.,Rezine, Ahmed,Rümmer, Philipp,Stenman, Jari(2014).String constraints for verification.CAV
  4. Buchi, J. R.,Senger, S.(1988).Definability in the existential theory of concate- nation and undecidable extensions of this theory.Z. Math. Logik Grundlagen Math.
  5. D'Silva, V.,Kroening, D.,Weissenbacher, G.(2008).A Survey of Automated Techniques for Formal Software Verification.IEEE Trans. on CAD of Integrated Circuits and Systems,27(7),1165-1178.
  6. Ganesh, V.,Minnes, M.,Solar-Lezama, A.,Rinard, M.(2013).Word equations with length constraints: Whats decidable?.Hardware and Software: Verification and Testing
  7. Jin, X.,Hu, X.,Ying, K.,Du, W.,Yin, H.,Peri, G. N.(2014).Code Injection Attacks on HTML5-based Mobile Apps: Characterization, Detection and Mitigation.Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security (CCS '14).
  8. Makanin, G.S.(1977).The problem of solvability of equations in a free semigroup.Mathematics of the USSR-Sbornik,32(2),129-198.
  9. Moura, L. D.,Bjorner, N.(2008).Z3: An efficient SMT solver. In Proceedings of the Theory and Practice of Software.14th International Conference on Tools and Algorithms for the Construction and Analysis of Systems, TACAS'08/ETAPS'08
  10. Saxena, P,Akhawe, D.,Hanna, S.,Mao, F.,McCamant, S.,Song, D.(2010).A Symbolic Execution Framework for JavaScript.IEEE Symposium on Security and Privacy
  11. Zheng, Y.,Zhang, X.,Ganesh, V.(2013).Z3-str: A Z3-based string solver for web a pplication analysis.Proceedings of the 2013 9th Joint Meeting on Foundations of Software Engineering, ESEC/FSE 2013,New York, NY, USA: