Publication | Closed Access
TAJ
302
Citations
31
References
2009
Year
Unknown Venue
Software MaintenanceEngineeringTaint AnalysisInformation SecuritySoftware EngineeringSource Code AnalysisAttack VectorsSoftware AnalysisInformation-flow AnalysisVulnerability Assessment (Computing)Systems EngineeringStatic AnalysisSecurity TestingComputer EngineeringComputer ScienceStatic Program AnalysisSoftware SecurityProgram AnalysisSoftware Testing
Taint analysis, a form of information-flow analysis, establishes whether values from untrusted methods and parameters may flow into security-sensitive operations. Taint analysis can detect many common vulnerabilities in Web applications, and so has attracted much attention from both the research community and industry. However, most static taint-analysis tools do not address critical requirements for an industrial-strength tool. Specifically, an industrial-strength tool must scale to large industrial Web applications, model essential Web-application code artifacts, and generate consumable reports for a wide range of attack vectors.
| Year | Citations | |
|---|---|---|
Page 1
Page 1