Collected research
Automatic Generation of XSS and SQL Injection Attacks with Goal-Directed Model Checking
QED compiles a PQL taint specification into a static analysis that prunes candidate URL sequences, then hands the survivors to the Java PathFinder model checker, which returns a concrete multi-request attack plus an execution trace and no false positives. Session data-flow dependence and non-repetition cut the space. Found 10 SQL injections and 13 XSS bugs in 130k lines of Struts apps.
Record
- Researcher
- Michael Martin and Monica S. Lam
- Published by
- usenix.org
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Michael Martin and Monica S. Lam, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .