Menu
MIT's new bug finder uncovers flaws in Web apps in 64 seconds

MIT's new bug finder uncovers flaws in Web apps in 64 seconds

It found 23 new vulnerabilities in 50 popular Web applications written with Ruby on Rails

MIT's new debugging system found 23 previously undiagnosed security flaws. Credit: MIT News

MIT's new debugging system found 23 previously undiagnosed security flaws. Credit: MIT News

Finding bugs in Web applications is an ongoing challenge, but a new tool from MIT exploits some of the idiosyncrasies in the Ruby on Rails programming framework to quickly uncover new ones.

In tests on 50 popular Web applications written using Ruby on Rails, the system found 23 previously undiagnosed security flaws, and it took no more than 64 seconds to analyze any given program.

Ruby on Rails is distinguished from other frameworks because it defines even its most basic operations in libraries. MIT's researchers took advantage of that fact by rewriting those libraries so that the operations defined in them describe their own behavior in a logical language.

That turns the Rails interpreter, which converts high-level Rails programs into machine-readable code, into a static-analysis tool that describes how data flows through the program. The result is that running a Rails program through the interpreter produces a formal, line-by-line description of how the program handles data.

Dubbed Space, the new debugger focuses on a program’s data-access procedures using a simple logical model that describes what operations a user can perform on what data and under what circumstances. From the descriptions generated by the hacked libraries, Space can automatically determine whether the program adheres to those models; if it doesn’t, there’s likely to be a security flaw.

The researchers will present their results next month at the International Conference on Software Engineering.

Subscribe here for up-to-date channel news

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Featured

Slideshows

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

Revealed at a glitzy bash in Sydney at the Ivy Penthouse, the first StorageCraft Partner Awards locally saw the vendor honour its top-performing partners with ASI Solutions, SMBiT Pro, Webroot, ACA Pacific and Soft Solutions New Zealand taking home the top awards. Photos by Maria Stefina.

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards
Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip

Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip

​Synnex and Lenovo hosted 18 resellers for an action-packed weekend adventure in RotoVegas, taking in white water rafting on the Kaituna River, as well as quad biking and dinner at Stratosfare​, overlooking Lake Rotorua at the top of Mount Ngongotaha​. Photos by Synnex.

Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip
Show Comments