Collected research
SynthDB: Synthesizing Database via Program Analysis for Security Testing of Web Applications
Dynamic scanners miss vulnerable code in database-backed PHP applications because those paths are only reachable when the database holds the right data. SynthDB uses concolic execution to learn the constraints linking PHP code to its SQL queries and synthesizes a database satisfying them, lifting Burp Suite detection to 76.8 percent and uncovering 33 previously unknown vulnerabilities.
Record
- Researcher
- An Chen, Jiho Lee, Basanta Chaulagain, Yonghwi Kwon and Kyu Hyung Lee
- Published by
- NDSS Symposium
- Topic
- Other
In the archive
Related sources
- NDSS 2023 - SynthDB: Synthesizing Database via Program Analysis for Security Testing of Web Apps
- NDSS 2023 - SynthDB: Synthesizing Database via Program Analysis for Security Testing of Web Apps
Tags
This page is the archive's own catalogue record. The research is the work of An Chen, Jiho Lee, Basanta Chaulagain, Yonghwi Kwon and Kyu Hyung Lee, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .