Automatically Fixing Security Vulnerabilities in Java Code (1/3)
Tue 2:00-2:45 pm - Galleria I
Automatically Fixing Security Vulnerabilities in Java Code
Aharon Abadi, IBM Research - Haifa, Israel
Ran Ettinger, IBM Research - Haifa, Israel
Yishai A. Feldman, IBM Research - Haifa, Israel
Mati Shomrat, Tel Aviv University, Israel
We present two algorithms for automatic remediation of security vulnerabilities in web applications. One correctly places sanitizers in the code, and the other replaces Statement by PreparedStatement. The demonstration will show how vulnerabilities flagged by a commercial security scanner are automatically fixed by an Eclipse plugin.




