New Static Analysis Method Can Help Find Security Flaws in Web Apps: Study

Advertisement
By Press Trust of India | Updated: 18 April 2016 12:54 IST
MIT researchers have developed a system that can quickly comb through tens of thousands of lines of application codes to find security flaws in popular web applications.

In tests on 50 popular applications written using Web programming framework Ruby on Rails, the system found 23 previously undiagnosed security flaws, and took no more than 64 seconds to analyse any given program.

According to researchers from Massachusetts Institute of Technology (MIT) in the US, the new system uses a technique called static analysis which seeks to describe in a very general way how data flows through a program.

"The classic example of this is if you wanted to do an abstract analysis of aprogram that manipulates integers, you might divide the integers into the positive integers, the negative integers, and zero," said Daniel Jackson from MIT.

Advertisement

The static analysis would then evaluate every operation in the program according to its effect on integers' signs.

Advertisement

Adding two positives yields a positive; adding two negatives yields a negative; multiplying two negatives yields a positive; and so on, researchers said.

"The problem with this is that it cannot be completely accurate, because you lose information. If you add a positive and a negative integer, you do not know whether the answer will be positive, negative, or zero," said Jackson.

Advertisement

"Most work on static analysis is focused on trying to make the analysis more scalable and accurate to overcome those sorts of problems," he said.

With Web applications, however, the cost of accuracy is prohibitively high, Jackson said.

Advertisement

"Theprogram under analysis is just huge. Even if you wrote a small program, it sits atop a vast edifice of libraries and plug-ins and frameworks," he said.

"So when you look at something like a Web application written in language like Ruby on Rails, if you try to do a conventional static analysis, you typically find yourself mired in this huge bog. And this makes it really infeasible in practice," he added.

A library is a compendium of code that programmers tend to use over and over again. Rather than rewriting the same functions for each new program, a programmer can just import them from a library, researchers said.

Ruby on Rails - or Rails - has the peculiarity of defining even its most basic operations in libraries. Every addition, every assignment of a particular value to a variable, imports code from a library, they said.

Researchers rewrote those libraries so that the operations defined in them describe their own behavior in a logical language. That turns the Rails interpreter, which converts high-level Rails programs into machine-readable code, into a static-analysis tool.

They identified seven different ways in which Web applications typically control access to data. Some data are publicly available, some are available only to users who are currently logged in, some are private to individual users, some users - administrators - have access to select aspects of everyone's data, and so on.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apps, Internet, MIT, Science, Web Apps
Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  4. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  5. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  6. Airtel Discontinues These Prepaid Recharge Packs in India
  7. Nothing Phone 3a Lite Goes on Sale in India at This Price
  8. OTT Releases of the Week (Dec 1 – Dec 7): Know What to Watch
  9. Here's When Samsung Might Launch the Galaxy Watch Ultra 2
  10. Apple Announces App Store Awards 2025 Winners: Check List
  1. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  2. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  3. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  4. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  5. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  6. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  7. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  8. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  9. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  10. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.