PHP DASTURLASH TILIDA STATIK TAHLIL USULI ORQALI ZAIFLIKLARNI ANIQLASH
Keywords:
statik tahlil, leksik tahlil, semantik tahlil, boshqarish oqimi tahlili, ma’lumotlar oqimi tahlili, potentsial zaiflik funksiyalari, Taint tahlili, masofadan tizim buyruqlarni amalga oshirish zaifligi, ichki jarayonlar tahlili, tashqi jarayonlar tahliliAbstract
Ushbu maqolada eng ko‘p foydalaniladigan dasturlash tillaridan biri hisoblangan php dasturlash tilida yozilgan dasturlarning kodidagi zaifliklarni aniqlash uchun statik tahlilni amalga oshiruvchi tahliliy vositani yaratish uchun talab etiladigan bosqichlar haqida so’z yuritiladi.
References
Nico L. de Poel, Automated Security Review of PHP Web Applications with Static Code Analysis, 2010.
Get Started with PHP Static Code Analysis [Elektron resurs]. -Kirish tartibi: https://deliciousbrains.com/php-static-code-analysis/
Interprocedural analysis (IPA) [Elektron resurs]. -Kirish tartibi: https://www.ibm.com/docs/en/i/7.2?topic=techniques-interprocedural-analysis-ipa
Jiazhen Zhao et al, WTA: A Static Taint Analysis Framework for PHP Webshell, 2021.