Skip to topic | Skip to bottom


Main.GLChengr1.2 - 02 May 2007 - 19:22 - LeonMoonen

Start of topic | Skip to actions

Java Security Vulnerabilities Detection with Static Analysis

G.L. Cheng

Security in software plays an important role in todays society as computer networking is getting more and more important. Security measures are taken to protect private information, but bad programming practices can still cause security vulnerabilities in software systems. Source code analysis tools can be used to detect such security vulnerabilities automatically. The use of these tools helps to improve the quality and security of software systems and could prevent future problems.

The class of security vulnerabilities called input validation vulnerabilities can be detected using static taint analysis. The design and implementation of such a tool are the subject of this paper. This tool detects input validation vulnerabilities in source code written in the Java programming language. This paper also describes in detail how to deal with complexities related to the object oriented nature of Java.

The tool first derives a graph structured model from the source code. This graph structured model captures data dependency relations between important program elements. This graph model is then analyzed using taint analysis to detect potential input validation vulnerabilities.

MSc project performed in the context of the ASSESS Project.

I Attachment sort Action Size Date Who Comment
glcheng_mscthesis.pdf manage 874.8 K 14 Mar 2007 - 15:15 LeonMoonen MSc Thesis G.L. Cheng

Copyright © 2003-2017, Software Engineering Research Group, Delft University of Technology, The Netherlands