WHIP: Improving Static Vulnerability Detection in Web Application by Forcing tools to Collaborate
Feras Al Kassar, Luca Compagna, Davide Balzarotti
摘要
Improving the accuracy of static application security testing (SAST) is key to fight critical vulnerabilities and increase the security of the Web. However, even state-ofthe-art commercial tools have many blind spots that limit their ability to properly analyze modern code and therefore to discover complex inter-procedural vulnerabilities. In this paper, we present WHIP, the first approach that enables SAST tools to 'collaborate' by sharing information that can help them to overcome each other's limitations. Our technique only operates on the application source code by using different tools as oracle to search for signs of interrupted data flows. When we discover such obstacles we inject alternative paths that circumvent the piece of code that SAST tools were not able to handle correctly. We conducted extensive experiments by analyzing over 100 popular PHP projects with more than 1,000 stars on Github. Our experiments show that our approach enables two popular SAST tools to increase their coverage of the applications' source code, resulting in an increase of up to 25% in the number of high-severity alerts. We manually inspected 30% of the novel 9,226 new alerts obtained by WHIP and responsibly disclosed 35 zero days injection vulnerabilities over 14 applications. This idea of combining the alarms generated by different static analysis tools is also often supported by researchers. For example, Nunes et al. [28] performed an empirical study of combining the results of static tools. Muske et al. [27] published instead a survey about research directions on handling static analysis alarms. The authors cite many papers that discuss the concept of alarms ranking, where the severity of an alarm is chosen based on how many tools raise the same alert.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- SSRF vs. Developers: A Study of SSRF-Defenses in PHP ApplicationsMalte Wessels, Simon Koch, Giancarlo Pellegrino, Martin JohnsUSENIX Security 2024 · 被引用 8 次
- Fuzzing the PHP Interpreter via Dataflow FusionYuancheng Jiang, Chuqi Zhang, Bonan Ruan, Jiahao Liu 等USENIX Security 2025
它引用的顶会 Paper4
- An empirical study on the effectiveness of static C code analyzers for vulnerability detectionStephan Lipp, Sebastian Banescu, Alexander PretschnerISSTA 2022 · 被引用 99 次
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 被引用 85 次
- Revealing injection vulnerabilities by leveraging existing testsKatherine Hough, Gebrehiwet B. Welearegai, Christian Hammer, Jonathan BellICSE 2020 · 被引用 7 次
- Testability Tarpits: the Impact of Code Patterns on the Security Testing of Web ApplicationsFeras Al Kassar, Giulia Clerici, Luca Compagna, Davide Balzarotti 等NDSS 2022
相关 Paper
- SynthDB: Synthesizing Database via Program Analysis for Security Testing of Web ApplicationsAn Chen, Jiho Lee, Basanta Chaulagain, Yonghwi Kwon 等NDSS 2023
- CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web ApplicationsYichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo 等ICSE 2026
- ZIPPER: Static Taint Analysis for PHP Applications with Precision and EfficiencyXinyi Wang, Yeting Li, Jie Lu, Shizhe Cui 等USENIX Security 2025
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
- Comparison and Evaluation on Static Application Security Testing (SAST) Tools for JavaKaixuan Li, Sen Chen, Lingling Fan, Ruitao Feng 等FSE 2023 · 被引用 43 次
