USENIX Security2023Top-tier venue
WHIP: Improving Static Vulnerability Detection in Web Application by Forcing tools to Collaborate
Feras Al Kassar, Luca Compagna, Davide Balzarotti
Abstract
Improving the accuracy of static application security testing (SAST) is key to fight critical vulnerabilities and increase the security of the Web. However, even state-ofthe-art commercial tools have many blind spots that limit their ability to properly analyze modern code and therefore to discover complex inter-procedural vulnerabilities. In this paper, we present WHIP, the first approach that enables SAST tools to 'collaborate' by sharing information that can help them to overcome each other's limitations. Our technique only operates on the application source code by using different tools as oracle to search for signs of interrupted data flows. When we discover such obstacles we inject alternative paths that circumvent the piece of code that SAST tools were not able to handle correctly. We conducted extensive experiments by analyzing over 100 popular PHP projects with more than 1,000 stars on Github. Our experiments show that our approach enables two popular SAST tools to increase their coverage of the applications' source code, resulting in an increase of up to 25% in the number of high-severity alerts. We manually inspected 30% of the novel 9,226 new alerts obtained by WHIP and responsibly disclosed 35 zero days injection vulnerabilities over 14 applications. This idea of combining the alarms generated by different static analysis tools is also often supported by researchers. For example, Nunes et al. [28] performed an empirical study of combining the results of static tools. Muske et al. [27] published instead a survey about research directions on handling static analysis alarms. The authors cite many papers that discuss the concept of alarms ranking, where the severity of an alarm is chosen based on how many tools raise the same alert.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 42fe4e27-85be-4bcb-9d06-e9846944035aCited by top-tier papers2
- SSRF vs. Developers: A Study of SSRF-Defenses in PHP ApplicationsMalte Wessels, Simon Koch, Giancarlo Pellegrino, Martin JohnsUSENIX Security 2024 · 8 citations
- Fuzzing the PHP Interpreter via Dataflow FusionYuancheng Jiang, Chuqi Zhang, Bonan Ruan, Jiahao Liu et al.USENIX Security 2025
Builds on4
- An empirical study on the effectiveness of static C code analyzers for vulnerability detectionStephan Lipp, Sebastian Banescu, Alexander PretschnerISSTA 2022 · 99 citations
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 85 citations
- Revealing injection vulnerabilities by leveraging existing testsKatherine Hough, Gebrehiwet B. Welearegai, Christian Hammer, Jonathan BellICSE 2020 · 7 citations
- Testability Tarpits: the Impact of Code Patterns on the Security Testing of Web ApplicationsFeras Al Kassar, Giulia Clerici, Luca Compagna, Davide Balzarotti et al.NDSS 2022
Related papers
- SynthDB: Synthesizing Database via Program Analysis for Security Testing of Web ApplicationsAn Chen, Jiho Lee, Basanta Chaulagain, Yonghwi Kwon et al.NDSS 2023
- CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web ApplicationsYichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo et al.ICSE 2026
- ZIPPER: Static Taint Analysis for PHP Applications with Precision and EfficiencyXinyi Wang, Yeting Li, Jie Lu, Shizhe Cui et al.USENIX Security 2025
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars et al.USENIX Security 2024 · 45 citations
- Comparison and Evaluation on Static Application Security Testing (SAST) Tools for JavaKaixuan Li, Sen Chen, Lingling Fan, Ruitao Feng et al.FSE 2023 · 43 citations
