International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1703677

1703677 Vol 6 · Issue 1 Download Paper

Detecting And Removing Vulnerabilities in Web Applications Using Data Mining and Static Analysis

Asha Amandeep Kaur Abhishek Aishwarya Patil Kailash

Subject area: Science,Engineering and Technology  ·  Area of research: Cyber Security

Abstract

With the advent of new technologies and applications, the web today is expanding faster than ever. Web application security has been an important subject of research in the last few years, yet it still remains a challenging problem. The issues arise due to vulnerable source codes that are written in unsafe languages like PHP. With the use of static analysis over the source code, we can detect the input vulnerabilities in the web application. However, the static analysis of the source code often create false positives, and it takes a lot of effort to fix the code. Through our paper, we delve into the approach of detecting vulnerabilities of the web application, but with lesser false positives. With the help of data mining, we remove the false positives generated. Here we will do programmed code amendment by embedding fixes in the source code. Afterwards diverse testing techniques like regression testing will be used to ensure if the code after rectification runs correctly and the points of vulnerability are removed. We materialize our research and this approach with the help of a WAP instrument. Consequently, we perform a trial assessment on numerous web applications with PHP source code to guarantee the accuracy of our software.

Keywords

Vulnerabilities, Static Analysis, Data mining, False Positives.

References

[1] L. K. Shar: Predicting common web application vulnerabilities from input validation and sanitization code patterns. Automated Software Engineering (ASE), 27th IEEE/ACM International Conference, 2012.

[2] N. L. de Poel: Automated security review of PHP web applications with static code analysis. ACM 23rd international conference on World Wide Web, 2014.

[3] Y.W. Huang: Securing web application code by static analysis and runtime protection. ACM 1-58113-844- X/04/0005, WWW 2004.

[4] L. K. Shar, H. B. K. Tan: Mining SQL injection and cross site scripting vulnerabilities. International Conference on Software Engineering, 2012.

[5] Sonam Panda, Ramani S: Protection of Web Application against SQL Injection Attacks. IJMER Vol 3, Issue.1, Jan-Feb 2013

[6] Iberia Medeiros, Numo Neves: Detection of web application vulnerabilities using static analysis. IEEE transaction on reliability.

[7] Symantec, Internet threat report. 2012 trends, vol. 18, Apr. 2013.

[8] Ashwani Garg, Shekhar Singh: A Review on Web Application Security Vulnerabilities. IJARSCE, Volume 3, Issue 1, January 2013.

How to cite this paper

Asha, Amandeep Kaur, Abhishek, Aishwarya Patil, Kailash "Detecting And Removing Vulnerabilities in Web Applications Using Data Mining and Static Analysis" Iconic Research And Engineering Journals Volume 6 Issue 1 2022 Page 452-456
Asha, Amandeep Kaur, Abhishek, Aishwarya Patil, Kailash "Detecting And Removing Vulnerabilities in Web Applications Using Data Mining and Static Analysis" Iconic Research And Engineering Journals, vol. 6, no. 1, Jul. 2022
Asha, Amandeep Kaur, Abhishek, Aishwarya Patil, Kailash (2022). Detecting And Removing Vulnerabilities in Web Applications Using Data Mining and Static Analysis. Iconic Research And Engineering Journals, 6(1).
Asha, Amandeep Kaur, Abhishek, Aishwarya Patil, Kailash "Detecting And Removing Vulnerabilities in Web Applications Using Data Mining and Static Analysis" Iconic Research And Engineering Journals, vol. 6, no. 1, Jul. 2022.
@article{1703677,
      author = {Asha, Amandeep Kaur, Abhishek, Aishwarya Patil, Kailash},
      title = {Detecting And Removing Vulnerabilities in Web Applications Using Data Mining and Static Analysis},
      journal = {Iconic Research And Engineering Journals},
      year = {2022},
      volume = {6},
      number = {1},
      pages = {452-456},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1703677.pdf},
      abstract = {With the advent of new technologies and applications, the web today is expanding faster than ever. Web application security has been an important subject of research in the last few years, yet it still remains a challenging problem. The issues arise due to vulnerable source codes that are written in unsafe languages like PHP. With the use of static analysis over the source code, we can detect the input vulnerabilities in the web application. However, the static analysis of the source code often create false positives, and it takes a lot of effort to fix the code. Through our paper, we delve into the approach of detecting vulnerabilities of the web application, but with lesser false positives. With the help of data mining, we remove the false positives generated. Here we will do programmed code amendment by embedding fixes in the source code. Afterwards diverse testing techniques like regression testing will be used to ensure if the code after rectification runs correctly and the     points      of      vulnerability      are      removed. We materialize our research and this approach with the help of a WAP instrument. Consequently, we perform a trial assessment on numerous web applications with PHP source code to guarantee the accuracy of our software.},
      keywords = {Vulnerabilities, Static Analysis, Data mining, False Positives.},
      month = {July},
  }