STEPS TO BUILD STATIC CODE ANALYSIS TOOL TO DETECT VULNERABILITIES IN PHP PROGRAMMING LANGUAGE

Authors

  • Utepbergenov Yunus Qutlimuratovich Master’s Student of “Information Security” Faculty, Tashkent University of Information Technologies named after Muhammad al-Khwarizmi

Keywords:

static analysis, lexical analysis, semantic analysis

Abstract

This article discusses the steps required to create an analytical tool that performs static analysis to identify vulnerabilities in the code of programs written in the Php programming language, which is one of the most widely used programming languages.

References

Nico L. de Poel, Automated Security Review of PHP Web Applications with Static Code Analysis, 2010.

Get Started with PHP Static Code Analysis [Elektron resurs]. -Kirish tartibi: https://deliciousbrains.com/php-static-code-analysis/

Interprocedural analysis (IPA) [Elektron resurs]. -Kirish tartibi: https://www.ibm.com/docs/en/i/7.2?topic=techniques-interprocedural-analysis-ipa

Jiazhen Zhao et al, WTA: A Static Taint Analysis Framework for PHP Webshell, 2021.

Downloads

Published

2022-05-25

Issue

Section

Articles