نویسندگان
1 کارشناس ارشد مهندسی فناوری اطلاعات، دانشکده مهندسی برق و کامپیوتر، دانشگاه یزد
2 استادیار، دانشکده مهندسی برق و کامپیوتر، دانشگاه یزد
چکیده
کلیدواژهها
عنوان مقاله [English]
نویسندگان [English]
Nowadays, due to the increased use of web-based applications and storage and exchange of sensitive
inforamtion by this category of programs, it is necessary to detect security vulnerabilities and remove them
to keep them secure against the misuse of intrusions. In most cases, the Static Analysis is especially valuable
in security assurance and detection of security vulnerabilities, while dynamic analysis goal is finding
and debugging the errors. In this paper, we present a new approach that detects common vulnerabilities in
web applications by Probable Data Flow Analysis on Vulnerability Probability Graph. VPG is designed to
consider the points with more probable to vulnerability and PDF Analysis is designed for the increase of
accuracy in vulnerability detection. The proposed approach was tested on a few web applications and the
results were compared with a few other tools that we observed improvement in performance in some cases.
کلیدواژهها [English]