Academic Journals Database
Disseminating quality controlled scientific knowledge

Finding Vulnerabilities in Rich Internet Applications (Flex/AS3) Using Static Techniques

ADD TO MY LIST
 
Author(s): Sreenivasa Rao Basavala | Narendra Kumar | Alok Agarrwal

Journal: International Journal of Modern Education and Computer Science
ISSN 2075-0161

Volume: 4;
Issue: 1;
Start page: 33;
Date: 2012;
Original page

Keywords: Applications security Analysis | Static Analysis | Taint Analysis | Vulnerability Detection in Flex | Static Techniques | Action Script Security

ABSTRACT
The number and the importance of Rich Internet Applications (RIA) have increased rapidly over the last years. At the same time, the quantity and impact of security vulnerabilities in such rich internet applications (RIA) have increasing as well. Since manual code reviews are time consuming, error prone and costly and it need skilled developers or programmers to review the manual source code review, the need for automated solutions has become evident.In this paper, we address the problem of application security vulnerable detection in Adobe Flex (Rich Internet Applications) platform in web 2.0 applications by means of static source code analysis. To this end, we present precise analysis targeted at the unique reference semantics commonly found in RIA based web applications or widgets (small applications which will run on fly i.e. drag and drop) developed in Adobe Flex Framework or Action Script 3.0. Moreover, we enhance the quality and quantity of the generated vulnerability reports.

Tango Rapperswil
Tango Rapperswil

     Save time & money - Smart Internet Solutions