CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web Applications
Yichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo, V. N. Venkatakrishnan, Yinzhi Cao
摘要
PHP, a widely-used programming language in Web development, contains powerful dynamic features (e.g., dynamic function name construction), making static detection of taint-style vulnerabilities like SQL injection and XSS challenging. State-of-the-art (SoTA) static approaches perform call graph-guided backward dataflow tracking, thus failing to analyze those dynamic PHP features, like variable functions, and control structures, which results in high false positives and negatives. In this paper, we design and implement CoBrA, a context-, branch-sensitive approach to detect taint-style vulnerabilities in PHP-based Web applications. The key innovations are the abstract domain graph (ADG), which is used to efficiently guide the analysis, and a ‘‘stretch-relax’’ algorithm, which enables accurate resolution of PHP dynamic features and efficient inter-procedural taint propagation. Our evaluation of CoBrA’s prototype identified 54 zero-day vulnerabilities in 19 real-world applications with nine CVE identifiers assigned, achieved 88.66% detection rate with under 0.3% false positives on a PHP tarpits dataset, and outperformed four SoTA tools across all test datasets with reasonable time and space consumption.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 被引用 85 次
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 被引用 65 次
- Chainsaw: Chained Automated Workflow-based Exploit GenerationAbeer Alhuzali, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2016 · 被引用 52 次
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
- TChecker: Precise Static Inter-Procedural Analysis for Detecting Taint-Style Vulnerabilities in PHP ApplicationsChanghua Luo, Penghui Li, Wei MengCCS 2022 · 被引用 27 次
相关 Paper
- ZIPPER: Static Taint Analysis for PHP Applications with Precision and EfficiencyXinyi Wang, Yeting Li, Jie Lu, Shizhe Cui 等USENIX Security 2025
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang 等OOPSLA 2025 · 被引用 9 次
- Argus: All your (PHP) Injection-sinks are belong to usRasoul Jahanshahi, Manuel EgeleUSENIX Security 2024 · 被引用 1 次
- Predator: Directed Web Application Fuzzing for Efficient Vulnerability ValidationChenlin Wang, Wei Meng, Changhua Luo, Penghui LiS&P 2025
- FIXX: FInding eXploits from eXamplesNeil P. Thimmaiah, Yashashvi J. Dave, Rigel Gjomemo, V. N. VenkatakrishnanUSENIX Security 2025
