Page 223 - 《软件学报》2026年第7期
P. 223

2908                                                       软件学报  2026  年第  37  卷第  7  期


                 两类多数据流分析方法相结合的            Web  漏洞检测技术, 可在原型链污染后续利用等场景中实现应用; 目前的分析系
                 统将多数据流漏洞规则作为输入, 而规则本身的编写仍需要较多的专家知识, 后续可进一步探索基于大语言模型
                 的分析规则自动化生成技术, 以持续提升漏洞检测全流程的自动化能力.

                 References
                  [1]   OWASP TOP 10: 2021. 2025. https://owasp.org/Top10/
                  [2]   Static application security testing (SAST) software market size and forecast. 2023. https://www.verifiedmarketresearch.com/product/static-
                     application-security-testing-sast-software-market/
                  [3]   Tan T, Li Y. Tai-e: A developer-friendly static analysis framework for Java by harnessing the good designs of classics. In: Proc. of the
                     32nd ACM SIGSOFT Int’l Symp. on Software Testing and Analysis. Seattle: ACM, 2023. 1093–1105. [doi: 10.1145/3597926.3598120]
                  [4]   Li S, Kang MQ, Hou JW, Cao YZ. Mining node.js vulnerabilities via object dependence graph and query. In: Proc. of the 31st USENIX
                     Security Symp. Boston: USENIX, 2022. 143–160.
                  [5]   Kang MQ, Xu YC, Li S, Gjomemo R, Hou JW, Venkatakrishnan VN, Cao YZ. Scaling JavaScript abstract interpretation to detect and
                     exploit  node.js  taint-style  vulnerability.  In:  Proc.  of  the  2023  IEEE  Symp.  on  Security  and  Privacy.  San  Francisco:  IEEE,  2023.
                     1059–1076. [doi: 10.1109/SP46215.2023.10179352]
                  [6]   Luo CH, Li PH, Meng W. TChecker: Precise static inter-procedural analysis for detecting taint-style vulnerabilities in PHP applications.
                     In: Proc. of the 2022 ACM SIGSAC Conf. on Computer and Communications Security. Los Angeles: ACM, 2022. 2175–2188. [doi: 10.
                     1145/3548606.3559391]
                  [7]   Chen M, Tu TF, Zhang H, Wen QY, Wang WH. Jasmine: A static analysis framework for spring core technologies. In: Proc. of the 37th
                     IEEE/ACM Int’l Conf. on Automated Software Engineering. Rochester: ACM, 2022. 60. [doi: 10.1145/3551349.3556910]
                  [8]   Guo ZY, Kang MQ, Venkatakrishnan VN, Gjomemo R, Cao YZ. ReactAppScan: Mining react application vulnerabilities via component
                     graph. In: Proc. of the 2024 ACM SIGSAC Conf. on Computer and Communications Security. Salt Lake City: ACM, 2024. 585–599.
                     [doi: 10.1145/3658644.3670331]
                  [9]   Backes M, Rieck K, Skoruppa M, Stock B, Yamaguchi F. Efficient and flexible discovery of PHP application vulnerabilities. In: Proc. of
                     the 2017 IEEE European Symp. on Security and Privacy. Paris: IEEE, 2017. 334–349. [doi: 10.1109/EuroSP.2017.14]
                 [10]   Su H, Li F, Xu LL, Hu WB, Sun YJ, Sun Q, Chao HN, Huo W. Splendor: Static detection of stored XSS in modern Web applications. In:
                     Proc.  of  the  32nd  ACM  SIGSOFT  Int’l  Symp.  on  Software  Testing  and  Analysis.  Seattle:  ACM,  2023.  1043–1054.  [doi:  10.1145/
                     3597926.3598116]
                 [11]   Dahse J, Holz T. Static detection of second-order vulnerabilities in Web applications. In: Proc. of the 23rd USENIX Conf. on Security
                     Symp. San Diego: USENIX Association, 2014. 989–1003. [doi: 10.5555/2671225.2671288]
                 [12]   Balzarotti D, Cova M, Felmetsger VV, Vigna G. Multi-module vulnerability analysis of Web-based applications. In: Proc. of the 14th
                     ACM Conf. on Computer and Communications Security. Alexandria: ACM, 2007. 25–35. [doi: 10.1145/1315245.1315250]
                 [13]   She DD, Chen YZ, Shah A, Ray B, Jana S. Neutaint: Efficient dynamic taint analysis with neural networks. In: Proc. of the 2020 IEEE
                     Symp. on Security and Privacy. San Francisco: IEEE, 2020. 1527–1543. [doi: 10.1109/SP40000.2020.00022]
                 [14]   Cui BJ, Wang FW, Guo T, Dong GW, Zhao B. FlowWalker: A fast and precise off-line taint analysis framework. In: Proc. of the 4th Int’l
                     Conf. on Emerging Intelligent Data and Web Technologies. Xi’an: IEEE, 2013. 583–588. [doi: 10.1109/EIDWT.2013.105]
                 [15]   Ming J, Wu DH, Xiao GY, Wang J, Liu P. TaintPipe: Pipelined symbolic taint analysis. In: Proc. of the 24th USENIX Conf. on Security
                     Symp. Washington: USENIX Association, 2015. 65–80. [doi: 10.5555/2831143.2831148]
                 [16]   Cui BJ, Wang FW, Guo T, Dong GW. A practical off-line taint analysis framework and its application in reverse engineering of file
                     format. Computers & Security, 2015, 51: 1–15. [doi: 10.1016/j.cose.2015.02.006]
                 [17]   Redini N, Machiry A, Das D, Fratantonio Y, Bianchi A, Gustafson E, Shoshitaishvili Y, Kruegel C, Vigna G. BootStomp: On the security
                     of  bootloaders  in  mobile  devices.  In:  Proc.  of  the  26th  USENIX  Conf.  on  Security  Symp.  Vancouver:  USENIX  Association,  2017.
                     781–798. [doi: 10.5555/3241189.3241251]
                 [18]   Zhang  H,  Chen  WT,  Hao  Y,  Li  GR,  Zhai  YZ,  Zou  XC,  Qian  ZY.  Statically  discovering  high-order  taint  style  vulnerabilities  in  OS
                     kernels. In: Proc. of the 2021 ACM SIGSAC Conf. on Computer and Communications Security. ACM, 2021. 811–824. [doi: 10.1145/
                     3460120.3484798
                 [19]   Wikipedia. Program analysis. 2025. https://en.wikipedia.org/wiki/Program_analysis
                 [20]   Liskov  B.  A  history  of  CLU.  In:  History  of  Programming  Languages  II.  New  York:  ACM,  1996.  471–510.  [doi:  10.1145/234286.
                     1057826]
   218   219   220   221   222   223   224   225   226   227   228