• DocumentCode
    3176329
  • Title

    Using SQL Hotspots in a Prioritization Heuristic for Detecting All Types of Web Application Vulnerabilities

  • Author

    Smith, Ben ; Williams, Laurie

  • Author_Institution
    Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
  • fYear
    2011
  • fDate
    21-25 March 2011
  • Firstpage
    220
  • Lastpage
    229
  • Abstract
    Development organizations often do not have time to perform security fortification on every file in a product before release. One way of prioritizing security efforts is to use metrics to identify core business logic that could contain vulnerabilities, such as database interaction code. Database code is a source of SQL injection vulnerabilities, but importantly may be home to unrelated vulnerabilities. The goal of this research is to improve the prioritization of security fortification efforts by investigating the ability of SQL hotspots to be used as the basis for a heuristic for prediction of all vulnerability types. We performed empirical case studies of 15 releases of two open source PHP web applications: Word Press, a blogging application, and WikkaWiki, a wiki management engine. Using statistical analysis, we show that the more SQL hotspots a file contains per line of code, the higher the probability that file will contain any type of vulnerability.
  • Keywords
    Internet; SQL; Web sites; probability; search engines; security of data; software metrics; statistical analysis; SQL hotspots; SQL injection; Web application vulnerability; WikkaWiki; Word Press; blogging application; core business logic; database code; database interaction code; development organizations; open source PHP Web applications; prioritization heuristic; probability; security fortification efforts; statistical analysis; wiki management engine; Complexity theory; Databases; Mathematical model; Measurement; Predictive models; Security; Software; empirical; hotspots; prioritization; sql; sql injection; wikkawiki; wordpress;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Testing, Verification and Validation (ICST), 2011 IEEE Fourth International Conference on
  • Conference_Location
    Berlin
  • Print_ISBN
    978-1-61284-174-8
  • Electronic_ISBN
    978-0-7695-4342-0
  • Type

    conf

  • DOI
    10.1109/ICST.2011.15
  • Filename
    5770611