z-logo
open-access-imgOpen Access
Secure Code Generation for Web Applications
Author(s) -
Martin Johns,
Christian Beyerlein,
Rosemaria Giesecke,
Joachim Posegga
Publication year - 2010
Publication title -
lecture notes in computer science
Language(s) - English
Resource type - Book series
SCImago Journal Rank - 0.249
H-Index - 400
eISSN - 1611-3349
pISSN - 0302-9743
ISBN - 3-642-11746-5
DOI - 10.1007/978-3-642-11747-3_8
Subject(s) - computer science , sql injection , programming language , javascript , serialization , scripting language , cross site scripting , code (set theory) , string (physics) , java , web application , database , operating system , web application security , world wide web , web service , web development , query by example , set (abstract data type) , web search query , search engine , physics , quantum mechanics
A large percentage of recent security problems, such as Cross-site Scripting or SQL injection, is caused by string-based code injection vulnerabilities. These vulnerabilities exist because of implicit code creation through string serialization. Based on an analysis of the vulnerability class' underlying mechanisms, we propose a general approach to outfit modern programming languages with mandatory means for explicit and secure code generation which provide strict separation between data and code. Using an exemplified implementation for the languages Java and HTML/JavaScript respectively, we show how our approach can be realized and enforced.

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here
Accelerating Research

Address

John Eccles House
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom