• DocumentCode
    1966941
  • Title

    Preventing Input Validation Vulnerabilities in Web Applications through Automated Type Analysis

  • Author

    Scholte, Theodoor ; Robertson, William ; Balzarotti, Davide ; Kirda, Engin

  • Author_Institution
    SAP Res., Sophia Antipolis, France
  • fYear
    2012
  • fDate
    16-20 July 2012
  • Firstpage
    233
  • Lastpage
    243
  • Abstract
    Web applications have become an integral part of the daily lives of millions of users. Unfortunately, web applications are also frequently targeted by attackers, and critical vulnerabilities such as cross-site scripting and SQL injection are still common. As a consequence, much effort in the past decade has been spent on mitigating web application vulnerabilities. Current techniques focus mainly on sanitization: either on automated sanitization, the detection of missing sanitizers, the correctness of sanitizers, or the correct placement of sanitizers. However, these techniques are either not able to prevent new forms of input validation vulnerabilities such as HTTP Parameter Pollution, come with large runtime overhead, lack precision, or require significant modifications to the client and/or server infrastructure. In this paper, we present IPAAS, a novel technique for preventing the exploitation of cross-site scripting and SQL injection vulnerabilities based on automated data type detection of input parameters. IPAAS automatically and transparently augments otherwise insecure web application development environments with input validators that result in significant and tangible security improvements for real systems. We implemented IPAAS for PHP and evaluated it on five real-world web applications with known cross-site scripting and SQL injection vulnerabilities. Our evaluation demonstrates that IPAAS would have prevented 83% of SQL injection vulnerabilities and 65% of cross-site scripting vulnerabilities while incurring no developer burden.
  • Keywords
    SQL; Web services; abstract data types; client-server systems; document handling; security of data; IPAAS; PHP; SQL injection vulnerability; Web application vulnerability; XSS injection vulnerability; automated data type detection; automated sanitization; client-server infrastructure; input validation vulnerability prevention; missing sanitizer detection; real system; tangible security improvement; Context; Databases; HTML; Robustness; Runtime; Security; Vectors; cross-site scripting; input validation; security; sql injection; web application;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Software and Applications Conference (COMPSAC), 2012 IEEE 36th Annual
  • Conference_Location
    Izmir
  • ISSN
    0730-3157
  • Print_ISBN
    978-1-4673-1990-4
  • Electronic_ISBN
    0730-3157
  • Type

    conf

  • DOI
    10.1109/COMPSAC.2012.34
  • Filename
    6340148