JASMaint: Portable Multi-language Taint Analysis for the Web
Abel Stuker, Aäron Munsters, Angel Luis Scull Pupo, Laurent Christophe, Elisa Gonzalez Boix
Vrije Universiteit Brussel
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
Modern web applications integrate JavaScript code with more efficient languages compiling to WebAssembly, such as C, C++ or Rust. However, such multi-language applications challenge program understanding and increase the risk of security attacks. Dynamic taint analysis is a powerful technique used to uncover confidentiality and integrity vulnerabilities. The state of the art has mainly considered taint analysis targeting a single programming language, extended with a limited set of native extensions. To deal with data flows between the language and native extensions, typically taint signatures or models of those extensions have been derived from the extensions’ high-level source code. However, this does not scale for multi-language web applications as the WebAssembly modules evolve continuously and generally do not include their high-level source code.
逐年被引趋势
暂无年度引用数据
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AIAdvanced Malware Detection Techniques
Web Application Security Vulnerabilities · Security and Verification in Computing
参考文献 18
此处列出前 3 条