Publiora

Menghubungkan ke Publiora...

Publiora

Automated server-side model for recognition of security vulnerabilities in scripting languages

Abdel-Kader, Rabab F.Nashaat, MonaHabib, Mohamed I.Mahdi, Hani M. K.
International Journal of Electrical and Computer Engineering (IJECE) (Sinta 1)Vol. 0 No. 01 Desember 2020
DOI10.11591/ijece.v10i6.pp6061-6070

Abstrak

With the increase of global accessibility of web applications, maintaining a reasonable security level for both user data and server resources has become an extremely challenging issue. Therefore, static code analysis systems can help web developers to reduce time and cost. In this paper, a new static analysis model is proposed. This model is designed to discover the security problems in scripting languages. The proposed model is implemented in a prototype SCAT, which is a static code analysis Tool. SCAT applies the phases of the proposed model to catch security vulnerabilities in PHP 5.3. Empirical results attest that the proposed prototype is feasible and is able to contribute to the security of real-world web applications. SCAT managed to detect 94% of security vulnerabilities found in the testing benchmarks; this clearly indicates that the proposed model is able to provide an effective solution to complicated web systems by offering benefits of securing private data for users and maintaining web application stability for web applications providers.

Kata Kunci

Computer and InformaticsData flow computingData securityObject-oriented programmingSoftware protectionSoftware testing

Cari jurnal yang tepat untuk naskah Anda

MatchMind AI mencocokkan abstrak naskah Anda dengan ribuan jurnal terakreditasi dan menampilkan rekomendasi terbaik beserta alasannya.

Coba MatchMind

Lihat profil lengkap jurnal ini

Waktu review, biaya APC, statistik sitasi, indeksasi Scopus, dan banyak lagi.

Buka International Journal of Electrical and Computer Engineering (IJECE)

Artikel ini juga tersedia di situs resmi jurnal.

Automated server-side model for recognition of security vulnerabilities in scripting languages | International Journal of Electrical and Computer Engineering (IJECE) | Publiora