{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,23]],"date-time":"2025-12-23T00:29:53Z","timestamp":1766449793482,"version":"3.37.3"},"reference-count":16,"publisher":"World Scientific Pub Co Pte Ltd","issue":"09","funder":[{"name":"Local Science and Technology Development Fund Project","award":["226Z0701G"],"award-info":[{"award-number":["226Z0701G"]}]},{"DOI":"10.13039\/501100003787","name":"Natural Science Foundation of Hebei Province","doi-asserted-by":"publisher","award":["F2022203026"],"award-info":[{"award-number":["F2022203026"]}],"id":[{"id":"10.13039\/501100003787","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003787","name":"Natural Science Foundation of Hebei Province","doi-asserted-by":"publisher","award":["F2022203089"],"award-info":[{"award-number":["F2022203089"]}],"id":[{"id":"10.13039\/501100003787","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Science and Technology Project of Hebei Education Depaetment","award":["BJK2022029"],"award-info":[{"award-number":["BJK2022029"]}]},{"name":"Science and Technology Project of Hebei Education Department","award":["QN2021145"],"award-info":[{"award-number":["QN2021145"]}]},{"name":"Innovation Capability Improvement Plan Project of Hebei Province","award":["22567637H"],"award-info":[{"award-number":["22567637H"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Int. J. Soft. Eng. Knowl. Eng."],"published-print":{"date-parts":[[2023,9]]},"abstract":"<jats:p> Access control vulnerabilities that lead to elevated privileges are among the most dangerous vulnerabilities in Web applications. Most of the existing detection methods use dynamic or static analysis techniques alone, which suffer from high manual involvement, low automation, high leakage rate, low page coverage, and other deficiencies. To this end, this paper proposes a novel access control vulnerability detection method (DetAC) based on a sitemap model with global information representation. This method first constructs a static site-wide sitemap model based on the page link addresses in the Web application source code through static analysis techniques. After that, the application is logged in and executed dynamically with different role users. During this process, execution traces and request parameters are collected and converted into annotations to fill the corresponding edges of the static site-wide sitemap model. Then, the sitemap model with global information representation is obtained. This model can represent both the global control flow and data flow of the application. Then DetAC analyzes the role-based and user-based access control policies of the Web application based on the node reachability and annotated data features of the model. And according to the information such as role, user, and access resources, it generates attack vectors to achieve different roles and the same role of different users to access each other\u2019s resources. Finally, access control vulnerabilities are detected based on the equivalence of the results obtained using attack vector access and normal access to the Web application server. DetAC was validated on five real open-source Web applications, and the results showed that DetAC successfully detected up to 12 access control vulnerabilities, which are more than those of the traditional seven tools. The dynamic analysis page coverage rate was significantly improved during the detection process, reaching an average of 91.37%. <\/jats:p>","DOI":"10.1142\/s0218194023500298","type":"journal-article","created":{"date-parts":[[2023,5,22]],"date-time":"2023-05-22T01:32:39Z","timestamp":1684719159000},"page":"1327-1354","source":"Crossref","is-referenced-by-count":2,"title":["DetAC: Approach to Detect Access Control Vulnerability in Web Application Based on Sitemap Model with Global Information Representation"],"prefix":"10.1142","volume":"33","author":[{"given":"Jiadong","family":"Ren","sequence":"first","affiliation":[{"name":"School of Information Science and Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"},{"name":"The Key Laboratory of Software Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingyou","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Information Science and Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"},{"name":"The Key Laboratory of Software Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9867-8439","authenticated-orcid":false,"given":"Bing","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Information Science and Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"},{"name":"The Key Laboratory of Software Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ke","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Information Science and Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"},{"name":"The Key Laboratory of Software Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shangyang","family":"Li","sequence":"additional","affiliation":[{"name":"School of Information Science and Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"},{"name":"The Key Laboratory of Software Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qian","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Information Science and Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"},{"name":"The Key Laboratory of Software Engineering, Yanshan University, Qinhuangdao, Hebei, P.\u00a0R.\u00a0China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yue","family":"Chang","sequence":"additional","affiliation":[{"name":"Qi An Xin Technology Group Inc., Beijing, P.\u00a0R.\u00a0China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tao","family":"Cheng","sequence":"additional","affiliation":[{"name":"Qi An Xin Legendsec Information Technology (Beijing) Inc., Beijing, P.\u00a0R.\u00a0China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"219","published-online":{"date-parts":[[2023,8,31]]},"reference":[{"issue":"2","key":"S0218194023500298BIB005","first-page":"482","volume":"3","author":"Song H. G.","year":"2012","journal-title":"Inf. Sci. Technol."},{"issue":"9","key":"S0218194023500298BIB006","doi-asserted-by":"crossref","first-page":"190:1","DOI":"10.1145\/3474553","volume":"54","author":"Zhang B.","year":"2022","journal-title":"ACM Comput. Surv."},{"key":"S0218194023500298BIB007","first-page":"481","volume-title":"Proc. 8th ACM SIGSAC Symp. Information, Computer and Communications Security","author":"Li X. W.","year":"2013"},{"issue":"3","key":"S0218194023500298BIB008","doi-asserted-by":"crossref","first-page":"89","DOI":"10.1016\/j.jnca.2018.01.008","volume":"109","author":"Deepa G.","year":"2018","journal-title":"J. Netw. Comput. Appl."},{"volume-title":"Proc. 20th USENIX Security Symp.","year":"2011","author":"Sun F. Q.","key":"S0218194023500298BIB009"},{"key":"S0218194023500298BIB010","first-page":"73","volume-title":"Proc. 21st ACM Symp. Access Control Models and Technologies","author":"Zhu J.","year":"2016"},{"key":"S0218194023500298BIB011","first-page":"247","volume-title":"Proc. 27th Annu. Computer Security Applications Conf.","author":"Li X.","year":"2011"},{"key":"S0218194023500298BIB012","first-page":"49","volume-title":"Proc. 4th ACM Conf. Data and Application Security and Privacy","author":"Li X.","year":"2014"},{"issue":"12","key":"S0218194023500298BIB013","first-page":"2658","volume":"40","author":"Wen S.","year":"2017","journal-title":"Chin. J. Comput."},{"key":"S0218194023500298BIB014","first-page":"204","volume-title":"Proc. 7th Int. Conf. Information Systems Security and Privacy","author":"Kushnir M.","year":"2021"},{"key":"S0218194023500298BIB015","first-page":"690","volume-title":"Proc. 2014 ACM SIGSAC Conf. Computer and Communications Security","author":"Monshizadeh M.","year":"2014"},{"issue":"12","key":"S0218194023500298BIB016","first-page":"63","volume":"54","author":"Xia Z. J.","year":"2018","journal-title":"Comput. Eng. Appl."},{"key":"S0218194023500298BIB017","doi-asserted-by":"crossref","first-page":"247","DOI":"10.1109\/WCRE.2012.34","volume-title":"Proc. 2012 19th Working Conf. Reverse Engineering","author":"Gauthier F.","year":"2012"},{"key":"S0218194023500298BIB018","first-page":"27","volume-title":"Proc. 20th ACM Symp. Access Control Models and Technologies","author":"Le H. T.","year":"2015"},{"key":"S0218194023500298BIB019","doi-asserted-by":"crossref","first-page":"111109","DOI":"10.1016\/j.jss.2021.111109","volume":"184","author":"Le H. T.","year":"2022","journal-title":"J. Syst. Softw."},{"key":"S0218194023500298BIB020","doi-asserted-by":"crossref","first-page":"1069","DOI":"10.1145\/2048066.2048146","volume-title":"Proc. 2011 ACM Int. Conf. Object Oriented Programming Systems Languages & Applications","author":"Son S.","year":"2011"}],"container-title":["International Journal of Software Engineering and Knowledge Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.worldscientific.com\/doi\/pdf\/10.1142\/S0218194023500298","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,27]],"date-time":"2023-09-27T10:33:58Z","timestamp":1695810838000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.worldscientific.com\/doi\/10.1142\/S0218194023500298"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,31]]},"references-count":16,"journal-issue":{"issue":"09","published-print":{"date-parts":[[2023,9]]}},"alternative-id":["10.1142\/S0218194023500298"],"URL":"https:\/\/doi.org\/10.1142\/s0218194023500298","relation":{},"ISSN":["0218-1940","1793-6403"],"issn-type":[{"type":"print","value":"0218-1940"},{"type":"electronic","value":"1793-6403"}],"subject":[],"published":{"date-parts":[[2023,8,31]]}}}