Doctoral thesis (Dissertations and theses)
A Scalable and Accurate Hybrid Vulnerability Analysis Framework
Thome, Julian
2018
 

Files


Full Text
Thesis_JulianThome2018.pdf
Author postprint (1.29 MB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
vulnerability detection; string constraint solving; security auditing; static analysis; search-based software engineering
Abstract :
[en] As the Internet has become an integral part of our everyday life for activities such as e-mail, online-banking, shopping, entertainment, etc., vulnerabilities in Web software arguably have greater impact than vulnerabilities in other types of software. Vulnerabilities in Web applications may lead to serious issues such as disclosure of confidential data, integrity violation, denial of service, loss of commercial confidence/customer trust, and threats to the continuity of business operations. For companies these issues can result in significant financial losses. The most common and serious threats for Web applications include injection vulnerabilities, where malicious input can be “injected” into the program to alter its intended behavior or the one of another system. These vulnerabilities can cause serious damage to a system and its users. For example, an attacker could compromise the systems underlying the application or gain access to a database containing sensitive information. The goal of this thesis is to provide a scalable approach, based on symbolic execution and constraint solving, which aims to effectively find injection vulnerabilities in the server-side code of Java Web applications and which generates no or few false alarms, minimizes false negatives, overcomes the path explosion problem and enables the solving of complex constraints.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Software Verification and Validation Lab (SVV Lab)
Disciplines :
Computer science
Author, co-author :
Thome, Julian ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Language :
English
Title :
A Scalable and Accurate Hybrid Vulnerability Analysis Framework
Defense date :
06 April 2018
Institution :
Unilu - University of Luxembourg, Luxembourg
Degree :
Docteur en Informatique
Jury member :
Denaro, Giovanni
Gorla, Alessandra
Focus Area :
Security, Reliability and Trust
FnR Project :
FNR9132112 - A Scalable And Accurate Hybrid Vulnerability Analysis Framework, 2014 (01/09/2014-14/04/2018) - Julian Thomé
Funders :
FNR - Fonds National de la Recherche [LU]
Available on ORBilu :
since 19 April 2018

Statistics


Number of views
287 (64 by Unilu)
Number of downloads
1729 (46 by Unilu)

Bibliography


Similar publications



Contact ORBilu