Logo do repositório
 
Publicação

Monitoring web applications for vulnerability discovery and removal under attack

datacite.subject.fosDepartamento de Informáticapt_PT
dc.contributor.advisorNeves, Nuno Fuentecilla Maia Ferreira, 1969-
dc.contributor.advisorMedeiros, Ibéria Vitória de Sousa, 1971-
dc.contributor.authorAntunes, Paulo David Ferreira
dc.date.accessioned2018-11-09T12:52:42Z
dc.date.available2018-11-09T12:52:42Z
dc.date.issued2018
dc.date.submitted2018
dc.descriptionTese de mestrado, Engenharia Informática (Arquitetura, Sistemas e Redes de Computadores) Universidade de Lisboa, Faculdade de Ciências, 2018pt_PT
dc.description.abstractWeb applications are ubiquitous in our everyday lives, as they are deployed in the most diverse contexts and support a variety of services. The correctness of these applications, however, can be compromised by vulnerabilities left in their source code, often incurring in nefarious consequences, such as the theft of private data and the adulteration of information. This dissertation proposes a solution for the automatic detection and removal of vulnerabilities in web applications programmed in the PHP language. By monitoring the user interactions with the web applications with traditional attack discovery tools, it is possible to identify malicious inputs that are eventually provided by attackers. These in- puts are then explored by a directed static analysis approach, allowing for the discovery of potential security issues and the correction of bugs in the program. The solution was implemented and validated with a set of vulnerable web applications. The experimental results demonstrate that the tool is capable of detecting and correcting SQL Injection and XSS vulnerabilities. In total 174 vulnerabilities were found in 5 web applications, where 2 of these were previously unknown by the research community(i.e., they were ”zero-day” vulnerabilities).pt_PT
dc.identifier.tid202011402pt_PT
dc.identifier.urihttp://hdl.handle.net/10451/35306
dc.language.isoengpt_PT
dc.subjectVulnerabilidadespt_PT
dc.subjectAplicações webpt_PT
dc.subjectSegurança de softwarept_PT
dc.subjectAnálise estática de código direcionadapt_PT
dc.subjectCorreção de códigopt_PT
dc.subjectTeses de mestrado - 2018pt_PT
dc.titleMonitoring web applications for vulnerability discovery and removal under attackpt_PT
dc.typemaster thesis
dspace.entity.typePublication
rcaap.rightsopenAccesspt_PT
rcaap.typemasterThesispt_PT
thesis.degree.nameMestrado em Engenharia Informática (Arquitetura, Sistemas e Redes de Computadores)pt_PT

Ficheiros

Principais
A mostrar 1 - 1 de 1
A carregar...
Miniatura
Nome:
ulfc121861_tm_Paulo_Antunes.pdf
Tamanho:
916.05 KB
Formato:
Adobe Portable Document Format
Licença
A mostrar 1 - 1 de 1
Miniatura indisponível
Nome:
license.txt
Tamanho:
1.2 KB
Formato:
Item-specific license agreed upon to submission
Descrição: