USENIX Security2025Top-tier venue
ZIPPER: Static Taint Analysis for PHP Applications with Precision and Efficiency
Xinyi Wang, Yeting Li, Jie Lu, Shizhe Cui, Chenghang Shi, Qin Mai, Yunpei Zhang, Yang Xiao, Feng Li, Wei Huo
Abstract
PHP-based web applications constitute a significant portion of the Web infrastructure and are frequently targeted by attackers exploiting taint-style vulnerabilities. While static analysis has emerged as a preferred approach for detecting these vulnerabilities, two major challenges persist: accurately inferring dynamic values from PHP's dynamic features, and efficiently detecting taint vulnerabilities in large-scale applications. This paper presents ZIPPER, a novel static analysis framework that addresses these challenges through two key innovations. First, we introduce a context-sensitive, flow-sensitive valueset algorithm that precisely infers dynamic values by leveraging input validation patterns and framework API characteristics. Second, we implement an efficient, on-demand approach to taint analysis that incorporates object-sensitive and array index-sensitive analyses while maintaining efficiency through sparse data dependency graphs. Evaluation on 429 known taint-style vulnerabilities demonstrates ZIPPER's effectiveness with the highest precision of 68.34% and an impressive recall of 98.14%, outperforming existing approaches. Furthermore, application of ZIPPER to 100 popular PHP applications led to the discovery of 11 previously unknown vulnerabilities, resulting in 6 CVE assignments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7d7967bd-1dbc-4582-9aa0-52f9988a2dffBuilds on17
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 123 citations
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 85 citations
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 65 citations
- Chainsaw: Chained Automated Workflow-based Exploit GenerationAbeer Alhuzali, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2016 · 52 citations
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars et al.USENIX Security 2024 · 45 citations
Related papers
- CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web ApplicationsYichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo et al.ICSE 2026
- TChecker: Precise Static Inter-Procedural Analysis for Detecting Taint-Style Vulnerabilities in PHP ApplicationsChanghua Luo, Penghui Li, Wei MengCCS 2022 · 27 citations
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang et al.OOPSLA 2025 · 9 citations
- Predator: Directed Web Application Fuzzing for Efficient Vulnerability ValidationChenlin Wang, Wei Meng, Changhua Luo, Penghui LiS&P 2025
- Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web ApplicationsEnze Wang, Jianjun Chen, Wei Xie, Chuhan Wang et al.S&P 2024 · 15 citations
