Tuesday, 21 May 2024

 

 

LATEST NEWS Vijay Inder Singla Promises Comprehensive Development for Anandpur Sahib Chief Minister Bhagwant Mann campaigns for Gurmeet Khuddian Can Clean-Shaven CM Bhagwant Mann Uphold Sikh Values? SAD Asks 8 Popular Shiny Dixit Web Series List 2024 | 5 Dariya News Chief Minister Bhagwant Mann recites Kikkli-2 in Bathinda - Kikkli Kaleer Di Buri Halat Sukhbir Di SAD will terminate all water sharing agreements with Rajasthan and Haryana once it comes to power in the State- Sukhbir Singh Badal Amarinder Singh Raja Warring Takes On BJP And AAP In Ludhiana, Promised Real Solutions For Punjab On Bittu’s CBI threat, Warring says, BJP candidate feels demoralised, defeated already Gurjeet Singh Aujla met the shopkeepers in the hot afternoon AAP government did not pay the dues of employees and 12% DA - Gurjeet Aujla Keep Check on Intermittent growth of wild Cannabis Plants, Whether in and around populated areas, DC Aashika Jain to officials ORS Packets, Sweet and Cold drinking water, Shades and Tents apart from Coolers and fans will be the tools of the Mohali Admin to save polling staff and voters from Heatwave on Poll Day Kang and Singla should tell whether Rahul and Kejriwal are friends or enemies : Dr. Subhash Sharma Gujarat MLA campaigned for BJP candidate in Mohali Mouni Roy Net Worth 2024 | Know the Actress Mouni Roy Financial Empire DEO Sakshi Sawhney conducts inspection at 9 critical polling stations of Atam Nagar and Ludhiana South David Angu: Ready to Elevate India's Musical Heritage on the Global Stage Former Home Minister Anil Vij stepped out of his car to meet farmers AAP dealt major setbacks to the BJP and SAD in Bathinda and Ferozepur California Miramar University & Chandigarh Group of Colleges Jhanjeri signed strategic academic partnership Ahead Of June 1 Polls, Dc Dr. Senu Duggal Alongwith SSP Make Surprise Night Inspection Of BSF And Police Joint Nakas

 

New system finds security flaws in popular web apps

Listen to this article

Web Admin

Web Admin

5 Dariya News

New York , 16 Apr 2016

US researchers have created a new system that can quickly comb through tens of thousands of lines of application code to find security flaws in popular web-based apps.The system, developed at the Massachusetts Institute of Technology (MIT), uses a technique called static analysis, which seeks to describe, in a very general way, how data flows through a program.

"The classic example of this is if you wanted to do an abstract analysis of a program that manipulates integers, you might divide the integers into the positive integers, the negative integers, and zero," said Daniel Jackson, an MIT professor and the co-author of the study. The static analysis would then evaluate every operation in the program according to its effect on integers' signs. Adding two positives yields a positive; adding two negatives yields a negative; multiplying two negatives yields a positive; and so on.

"The problem with this is that it can't be completely accurate, because you lose information," Jackson said. "If you add a positive and a negative integer, you don't know whether the answer will be positive, negative, or zero. Most work on static analysis is focused on trying to make the analysis more scalable and accurate to overcome those sorts of problems," he added.With web applications, however, the cost of accuracy is prohibitively high. "The program under analysis is just huge," he said. "Even if you wrote a small program, it sits atop a vast edifice of libraries and plug-ins and frameworks. So when you look at something like a web application written in language like Ruby on Rails, if you try to do a conventional static analysis, you typically find yourself mired in this huge bog. And this makes it really infeasible in practice."That vast edifice of libraries, however, also gave Jackson and his former student Joseph Near, a way to make static analysis of programs written in Ruby on Rails practical.They exploited some peculiarities of the popular web programming framework to develop their system called "Space".

The researchers will present their results at the International Conference on Software Engineering to be held in Austin, Texas, in May this year.In his PhD work, Near used this general machinery to build three different debuggers for Ruby on Rails applications, each requiring different degrees of programmer involvement. Near identified seven different ways in which web applications typically control access to data. Some data are publicly available, some are available only to users who are currently logged in, some are private to individual users, some users -- administrators -- have access to select aspects of everyone's data, and so on.For each of these data-access patterns, Near developed a simple logical model that describes what operations a user can perform on what data, under what circumstances.From the descriptions generated by the hacked libraries, Space can automatically determine whether the program adheres to those models. If it does not, there's likely to be a security flaw.In tests on 50 popular web applications written using Ruby on Rails, the system found 23 previously undiagnosed security flaws, and it took no more than 64 seconds to analyse any given program.

 

Tags: STUDY

 

 

related news

 

 

 

Photo Gallery

 

 

Video Gallery

 

 

5 Dariya News RNI Code: PUNMUL/2011/49000
© 2011-2024 | 5 Dariya News | All Rights Reserved
Powered by: CDS PVT LTD