kirancodes.me
To Proof Maintenance & Beyond!

Derailer: interactive security analysis for web applications

Joseph P. Near, Daniel Jackson

Abstract

Derailer is an interactive tool for finding security bugs in web applications. Using symbolic execution, it enumerates the ways in which application data might be exposed. The user is asked to examine these exposures and classify the conditions under which they occur as security-related or not; in so doing, the user effectively constructs a specification of the application's security policy. The tool then highlights exposures missing security checks, which tend to be security bugs.

BibTeX
@inproceedings{Near-Jackson:ASE14,
  author    = {Joseph P. Near and
               Daniel Jackson},
  title     = {Derailer: interactive security analysis for web applications},
  booktitle = {ASE},
  pages     = {587--598},
  publisher = {{ACM}},
  year      = {2014},
}

Related papers