Return
Securing Large Applications Against Command Injections
DOI:10.1109/MAES.2009.5161718.png)
Abstract
En 中文
The ability to produce more secure software or to improve the security of existing software is a growing concern and a real challenge for the field of software engineering. Among the various existing types of software vulnerabilities, command injections are particularly common. It is a difficult problem to address, having seemingly endless variations. We present a unified, formal definition of command injections that, is not based on a particular technology and captures not only the existing variations but also the future instances of the problem. We then propose a simple, yet effective, strategy to deal with the problem in existing large applications, focusing on the cost-effectiveness of the method. We also report on successful experiments applying our solution to large commercial applications.
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
IF:
3.8
Papers:
2.1K
Citations:
2.5K
Organization
No organization information available
Cited Papers
no more

