Page 223 - 《软件学报》2026年第7期
P. 223
2908 软件学报 2026 年第 37 卷第 7 期
两类多数据流分析方法相结合的 Web 漏洞检测技术, 可在原型链污染后续利用等场景中实现应用; 目前的分析系
统将多数据流漏洞规则作为输入, 而规则本身的编写仍需要较多的专家知识, 后续可进一步探索基于大语言模型
的分析规则自动化生成技术, 以持续提升漏洞检测全流程的自动化能力.
References
[1] OWASP TOP 10: 2021. 2025. https://owasp.org/Top10/
[2] Static application security testing (SAST) software market size and forecast. 2023. https://www.verifiedmarketresearch.com/product/static-
application-security-testing-sast-software-market/
[3] Tan T, Li Y. Tai-e: A developer-friendly static analysis framework for Java by harnessing the good designs of classics. In: Proc. of the
32nd ACM SIGSOFT Int’l Symp. on Software Testing and Analysis. Seattle: ACM, 2023. 1093–1105. [doi: 10.1145/3597926.3598120]
[4] Li S, Kang MQ, Hou JW, Cao YZ. Mining node.js vulnerabilities via object dependence graph and query. In: Proc. of the 31st USENIX
Security Symp. Boston: USENIX, 2022. 143–160.
[5] Kang MQ, Xu YC, Li S, Gjomemo R, Hou JW, Venkatakrishnan VN, Cao YZ. Scaling JavaScript abstract interpretation to detect and
exploit node.js taint-style vulnerability. In: Proc. of the 2023 IEEE Symp. on Security and Privacy. San Francisco: IEEE, 2023.
1059–1076. [doi: 10.1109/SP46215.2023.10179352]
[6] Luo CH, Li PH, Meng W. TChecker: Precise static inter-procedural analysis for detecting taint-style vulnerabilities in PHP applications.
In: Proc. of the 2022 ACM SIGSAC Conf. on Computer and Communications Security. Los Angeles: ACM, 2022. 2175–2188. [doi: 10.
1145/3548606.3559391]
[7] Chen M, Tu TF, Zhang H, Wen QY, Wang WH. Jasmine: A static analysis framework for spring core technologies. In: Proc. of the 37th
IEEE/ACM Int’l Conf. on Automated Software Engineering. Rochester: ACM, 2022. 60. [doi: 10.1145/3551349.3556910]
[8] Guo ZY, Kang MQ, Venkatakrishnan VN, Gjomemo R, Cao YZ. ReactAppScan: Mining react application vulnerabilities via component
graph. In: Proc. of the 2024 ACM SIGSAC Conf. on Computer and Communications Security. Salt Lake City: ACM, 2024. 585–599.
[doi: 10.1145/3658644.3670331]
[9] Backes M, Rieck K, Skoruppa M, Stock B, Yamaguchi F. Efficient and flexible discovery of PHP application vulnerabilities. In: Proc. of
the 2017 IEEE European Symp. on Security and Privacy. Paris: IEEE, 2017. 334–349. [doi: 10.1109/EuroSP.2017.14]
[10] Su H, Li F, Xu LL, Hu WB, Sun YJ, Sun Q, Chao HN, Huo W. Splendor: Static detection of stored XSS in modern Web applications. In:
Proc. of the 32nd ACM SIGSOFT Int’l Symp. on Software Testing and Analysis. Seattle: ACM, 2023. 1043–1054. [doi: 10.1145/
3597926.3598116]
[11] Dahse J, Holz T. Static detection of second-order vulnerabilities in Web applications. In: Proc. of the 23rd USENIX Conf. on Security
Symp. San Diego: USENIX Association, 2014. 989–1003. [doi: 10.5555/2671225.2671288]
[12] Balzarotti D, Cova M, Felmetsger VV, Vigna G. Multi-module vulnerability analysis of Web-based applications. In: Proc. of the 14th
ACM Conf. on Computer and Communications Security. Alexandria: ACM, 2007. 25–35. [doi: 10.1145/1315245.1315250]
[13] She DD, Chen YZ, Shah A, Ray B, Jana S. Neutaint: Efficient dynamic taint analysis with neural networks. In: Proc. of the 2020 IEEE
Symp. on Security and Privacy. San Francisco: IEEE, 2020. 1527–1543. [doi: 10.1109/SP40000.2020.00022]
[14] Cui BJ, Wang FW, Guo T, Dong GW, Zhao B. FlowWalker: A fast and precise off-line taint analysis framework. In: Proc. of the 4th Int’l
Conf. on Emerging Intelligent Data and Web Technologies. Xi’an: IEEE, 2013. 583–588. [doi: 10.1109/EIDWT.2013.105]
[15] Ming J, Wu DH, Xiao GY, Wang J, Liu P. TaintPipe: Pipelined symbolic taint analysis. In: Proc. of the 24th USENIX Conf. on Security
Symp. Washington: USENIX Association, 2015. 65–80. [doi: 10.5555/2831143.2831148]
[16] Cui BJ, Wang FW, Guo T, Dong GW. A practical off-line taint analysis framework and its application in reverse engineering of file
format. Computers & Security, 2015, 51: 1–15. [doi: 10.1016/j.cose.2015.02.006]
[17] Redini N, Machiry A, Das D, Fratantonio Y, Bianchi A, Gustafson E, Shoshitaishvili Y, Kruegel C, Vigna G. BootStomp: On the security
of bootloaders in mobile devices. In: Proc. of the 26th USENIX Conf. on Security Symp. Vancouver: USENIX Association, 2017.
781–798. [doi: 10.5555/3241189.3241251]
[18] Zhang H, Chen WT, Hao Y, Li GR, Zhai YZ, Zou XC, Qian ZY. Statically discovering high-order taint style vulnerabilities in OS
kernels. In: Proc. of the 2021 ACM SIGSAC Conf. on Computer and Communications Security. ACM, 2021. 811–824. [doi: 10.1145/
3460120.3484798
[19] Wikipedia. Program analysis. 2025. https://en.wikipedia.org/wiki/Program_analysis
[20] Liskov B. A history of CLU. In: History of Programming Languages II. New York: ACM, 1996. 471–510. [doi: 10.1145/234286.
1057826]

