Type-Based Taint Analysis for Java Web Applications [chapter]

Wei Huang, Yao Dong, Ana Milanova
2014 Lecture Notes in Computer Science  
Static taint analysis detects information flow vulnerabilities. It has gained considerable importance in the last decade, with the majority of work focusing on dataflow and points-to-based approaches. In this paper, we advocate type-based taint analysis. We present SFlow, a context-sensitive type system for secure information flow, and SFlow-Infer, a corresponding worst-case cubic inference analysis. Our approach effectively handles reflection, libraries and frameworks, features notoriously
more » ... icult for dataflow and points-to-based taint analysis. We implemented SFlow and SFlowInfer. Empirical results on 13 realworld Java web applications show that our approach is scalable and also precise, achieving false positive rate of 15%.
doi:10.1007/978-3-642-54804-8_10 fatcat:aydbrd7xtnd6zkbxf67kpy2azm