Lune

ICSE2026顶会

CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web Applications

Yichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo, V. N. Venkatakrishnan, Yinzhi Cao

2026年份

摘要

PHP, a widely-used programming language in Web development, contains powerful dynamic features (e.g., dynamic function name construction), making static detection of taint-style vulnerabilities like SQL injection and XSS challenging. State-of-the-art (SoTA) static approaches perform call graph-guided backward dataflow tracking, thus failing to analyze those dynamic PHP features, like variable functions, and control structures, which results in high false positives and negatives. In this paper, we design and implement CoBrA, a context-, branch-sensitive approach to detect taint-style vulnerabilities in PHP-based Web applications. The key innovations are the abstract domain graph (ADG), which is used to efficiently guide the analysis, and a ‘‘stretch-relax’’ algorithm, which enables accurate resolution of PHP dynamic features and efficient inter-procedural taint propagation. Our evaluation of CoBrA’s prototype identified 54 zero-day vulnerabilities in 19 real-world applications with nine CVE identifiers assigned, achieved 88.66% detection rate with under 0.3% false positives on a PHP tarpits dataset, and outperformed four SoTA tools across all test datasets with reasonable time and space consumption.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper9

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖