skip to main content
10.1145/2600176.2600194acmotherconferencesArticle/Chapter ViewAbstractPublication PageshotsosConference Proceedingsconference-collections
research-article

Type-specific languages to fight injection attacks

Published: 08 April 2014 Publication History

Abstract

Injection vulnerabilities have topped rankings of the most critical web application vulnerabilities for several years [1, 2]. They can occur anywhere where user input may be erroneously executed as code. The injected input is typically aimed at gaining unauthorized access to the system or to private information within it, corrupting the system's data, or disturbing system availability. Injection vulnerabilities are tedious and difficult to prevent.

References

[1]
CWE/SANS. http://cwe.mitre.org/top25/#Listing.
[2]
OWASP Top Ten Project. https://www.owasp.org/index.php/Category: ___ OWASP_Top_Ten_Project.
[3]
M. Bravenboer, E. Dolstra, and E. Visser. Preventing injection attacks with syntax embeddings. In GPCE, 2007.
[4]
B. Chess and J. West. Dynamic taint propagation: Finding vulnerabilities without attacking. Information Security Tech. Report, 2008.
[5]
A. Chlipala. Ur: statically-typed metaprogramming with type-level record computation. In PLDI, 2010.
[6]
S. Chong, J. Liu, A. C. Myers, X. Qi, K. Vikram, L. Zheng, and X. Zheng. Secure web applications via automatic partitioning. In SOSP, 2007.
[7]
B. J. Corcoran, N. Swamy, and M. Hicks. Cross-tier, Labeld-based Secuirty Enforcement for Web Applications. In ACM SIGMOD, 2009.
[8]
S. Erdweg, T. Rendel, C. Kästner, and K. Ostermann. SugarJ: library-based language extensibility. In OOPSLA, 2011.
[9]
S. Erdweg and F. Rieger. A Framework for Extensible Languages. In GPCE, 2013.
[10]
S. Hussein, P. Meredith, and G. Roşlu. Security-policy monitoring and enforcement with javamop. In PLAS, 2012.
[11]
B. Livshits and S. Chong. Towards Fully Automatic Placement of Security Sanitizers and Declassifiers. In POPL, 2013.
[12]
L. Nistor, D. Kurilova, S. Balzer, B. Chung, A. Potanin, and J. Aldrich. Wyvern: A Simple, Typed, and Pure Object-oriented Language. In MASPEGHI, 2013.
[13]
C. Omar, D. Kurilova, L. Nistor, B. Chung, A. Potanin, and J. Aldrich. Safely composable type-specific languages. To appear, ECOOP, 2014.
[14]
P. Saxena, D. Molnar, and B. Livshits. Scriptgard: automatic context-sensitive sanitization for large-scale legacy web applications. In ACM CCS, 2011.

Cited By

View all

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Other conferences
HotSoS '14: Proceedings of the 2014 Symposium and Bootcamp on the Science of Security
April 2014
184 pages
ISBN:9781450329071
DOI:10.1145/2600176
Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

Sponsors

  • No. Carolina State Univeresity: North Carolina State University

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 08 April 2014

Check for updates

Qualifiers

  • Research-article

Conference

HotSoS '14
Sponsor:
  • No. Carolina State Univeresity
HotSoS '14: Symposium and Bootcamp on the Science of Security
April 8 - 9, 2014
North Carolina, Raleigh, USA

Acceptance Rates

HotSoS '14 Paper Acceptance Rate 12 of 21 submissions, 57%;
Overall Acceptance Rate 34 of 60 submissions, 57%

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)5
  • Downloads (Last 6 weeks)0
Reflects downloads up to 06 Nov 2024

Other Metrics

Citations

Cited By

View all

View Options

Get Access

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media