loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Md. Imran Alam 1 ; 2 and Raju Halder 1

Affiliations: 1 Indian Institute of Technology Patna, India ; 2 Università Ca’ Foscari Venezia, Italy

Keyword(s): Database Applications, Taint Analysis, K Framework, Security.

Abstract: Maintaining the integrity of underlying databases of any information systems is one of the challenges. This could be either due to coding flaws or due to improper flow of information from source to sink in the associated database applications. Compromising this may lead to either disclosure of sensitive information to the attackers or illegitimately modification of private data stored in the databases. Taint analysis is a widely used program analysis technique that aims at averting malicious inputs from corrupting data values in critical computations of programs. In this paper, we propose K-DBTaint, a rewriting logic-based executable semantics for taint analysis of database applications in the K framework. We specify the semantics for a subset of SQL statements along with host imperative program statements. Our K semantics can be seen as a sound approximation of program semantics in the corresponding security type domain. With respect to the existing methods, K-DBTaint supports conte xt- and flow-sensitive analysis, reduces false alarms, and provides a scalable solution. Experimental evaluation on several PL/SQL benchmark codes demonstrates encouraging results as an improvement in the precision of the analysis. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.235.251.99

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Alam, M. and Halder, R. (2021). Tailoring Taint Analysis for Database Applications in the K Framework. In Proceedings of the 10th International Conference on Data Science, Technology and Applications - DATA; ISBN 978-989-758-521-0; ISSN 2184-285X, SciTePress, pages 370-377. DOI: 10.5220/0010618603700377

@conference{data21,
author={Md. Imran Alam. and Raju Halder.},
title={Tailoring Taint Analysis for Database Applications in the K Framework},
booktitle={Proceedings of the 10th International Conference on Data Science, Technology and Applications - DATA},
year={2021},
pages={370-377},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0010618603700377},
isbn={978-989-758-521-0},
issn={2184-285X},
}

TY - CONF

JO - Proceedings of the 10th International Conference on Data Science, Technology and Applications - DATA
TI - Tailoring Taint Analysis for Database Applications in the K Framework
SN - 978-989-758-521-0
IS - 2184-285X
AU - Alam, M.
AU - Halder, R.
PY - 2021
SP - 370
EP - 377
DO - 10.5220/0010618603700377
PB - SciTePress