<?xml version="1.0" encoding="utf-8"?>
<TEI xmlns="http://www.tei-c.org/ns/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:hal="http://hal.archives-ouvertes.fr/" xmlns:gml="http://www.opengis.net/gml/3.3/" xmlns:gmlce="http://www.opengis.net/gml/3.3/ce" version="1.1" xsi:schemaLocation="http://www.tei-c.org/ns/1.0 http://api.archives-ouvertes.fr/documents/aofr-sword.xsd">
  <teiHeader>
    <fileDesc>
      <titleStmt>
        <title>HAL TEI export of hal-01522368</title>
      </titleStmt>
      <publicationStmt>
        <distributor>CCSD</distributor>
        <availability status="restricted">
          <licence target="https://creativecommons.org/publicdomain/zero/1.0/">CC0 1.0 - Universal</licence>
        </availability>
        <date when="2026-05-19T08:55:07+02:00"/>
      </publicationStmt>
      <sourceDesc>
        <p part="N">HAL API Platform</p>
      </sourceDesc>
    </fileDesc>
  </teiHeader>
  <text>
    <body>
      <listBibl>
        <biblFull>
          <titleStmt>
            <title xml:lang="en">Sound and Static Analysis of Session Fixation Vulnerabilities in PHP Web Applications</title>
            <author role="aut">
              <persName>
                <forename type="first">Abdelouahab</forename>
                <surname>Amira</surname>
              </persName>
              <idno type="halauthorid">1169896-0</idno>
              <affiliation ref="#struct-139441"/>
            </author>
            <author role="aut">
              <persName>
                <forename type="first">Abdelraouf</forename>
                <surname>Ouadjaout</surname>
              </persName>
              <email type="md5">88071e6e43bfa8cdedf09199c9a4736e</email>
              <email type="domain">lip6.fr</email>
              <idno type="idhal" notation="string">aouadjaout</idno>
              <idno type="idhal" notation="numeric">9404</idno>
              <idno type="halauthorid" notation="string">40114-9404</idno>
              <idno type="ORCID">https://orcid.org/0000-0001-7248-5914</idno>
              <idno type="IDREF">https://www.idref.fr/253126290</idno>
              <affiliation ref="#struct-391379"/>
            </author>
            <author role="aut">
              <persName>
                <forename type="first">Abdelouahid</forename>
                <surname>Derhab</surname>
              </persName>
              <idno type="idhal" notation="numeric">777859</idno>
              <idno type="halauthorid" notation="string">1023508-777859</idno>
              <idno type="ORCID">https://orcid.org/0000-0002-6498-1528</idno>
              <affiliation ref="#struct-456208"/>
            </author>
            <author role="aut">
              <persName>
                <forename type="first">Nadjib</forename>
                <surname>Badache</surname>
              </persName>
              <idno type="halauthorid">235503-0</idno>
              <affiliation ref="#struct-92874"/>
              <affiliation ref="#struct-139441"/>
            </author>
            <editor role="depositor">
              <persName>
                <forename>Abdelraouf</forename>
                <surname>Ouadjaout</surname>
              </persName>
              <email type="md5">88071e6e43bfa8cdedf09199c9a4736e</email>
              <email type="domain">lip6.fr</email>
            </editor>
          </titleStmt>
          <editionStmt>
            <edition n="v1" type="current">
              <date type="whenSubmitted">2017-05-14 20:44:17</date>
              <date type="whenModified">2023-04-11 15:16:28</date>
              <date type="whenReleased">2017-05-14 20:44:17</date>
              <date type="whenProduced">2017-03-22</date>
            </edition>
            <respStmt>
              <resp>contributor</resp>
              <name key="445023">
                <persName>
                  <forename>Abdelraouf</forename>
                  <surname>Ouadjaout</surname>
                </persName>
                <email type="md5">88071e6e43bfa8cdedf09199c9a4736e</email>
                <email type="domain">lip6.fr</email>
              </name>
            </respStmt>
          </editionStmt>
          <publicationStmt>
            <distributor>CCSD</distributor>
            <idno type="halId">hal-01522368</idno>
            <idno type="halUri">https://hal.sorbonne-universite.fr/hal-01522368</idno>
            <idno type="halBibtex">amira:hal-01522368</idno>
            <idno type="halRefHtml">&lt;i&gt;CODASPY&lt;/i&gt;, Mar 2017, Scottsdale, Arizona, United States. Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy, 2017, &lt;a target="_blank" href="https://dx.doi.org/10.1145/3029806.3029838"&gt;&amp;#x27E8;10.1145/3029806.3029838&amp;#x27E9;&lt;/a&gt;</idno>
            <idno type="halRef">CODASPY, Mar 2017, Scottsdale, Arizona, United States. Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy, 2017, &amp;#x27E8;10.1145/3029806.3029838&amp;#x27E9;</idno>
            <availability status="restricted"/>
          </publicationStmt>
          <seriesStmt>
            <idno type="stamp" n="UPMC" corresp="SORBONNE-UNIVERSITE">Université Pierre et Marie Curie</idno>
            <idno type="stamp" n="CNRS">CNRS - Centre national de la recherche scientifique</idno>
            <idno type="stamp" n="LIP6" corresp="SORBONNE-UNIVERSITE">Laboratoire d'Informatique de Paris 6</idno>
            <idno type="stamp" n="UPMC_POLE_1" corresp="UPMC">UPMC Pôle 1</idno>
            <idno type="stamp" n="SORBONNE-UNIVERSITE">Sorbonne Université</idno>
            <idno type="stamp" n="SU-SCIENCES" corresp="SORBONNE-UNIVERSITE">Faculté des Sciences de Sorbonne Université</idno>
            <idno type="stamp" n="TEST-HALCNRS">Collection test HAL CNRS</idno>
            <idno type="stamp" n="ALLIANCE-SU"> Alliance Sorbonne Université</idno>
          </seriesStmt>
          <notesStmt>
            <note type="audience" n="2">International</note>
            <note type="invited" n="0">No</note>
            <note type="popular" n="0">No</note>
            <note type="peer" n="1">Yes</note>
            <note type="proceedings" n="1">Yes</note>
          </notesStmt>
          <sourceDesc>
            <biblStruct>
              <analytic>
                <title xml:lang="en">Sound and Static Analysis of Session Fixation Vulnerabilities in PHP Web Applications</title>
                <author role="aut">
                  <persName>
                    <forename type="first">Abdelouahab</forename>
                    <surname>Amira</surname>
                  </persName>
                  <idno type="halauthorid">1169896-0</idno>
                  <affiliation ref="#struct-139441"/>
                </author>
                <author role="aut">
                  <persName>
                    <forename type="first">Abdelraouf</forename>
                    <surname>Ouadjaout</surname>
                  </persName>
                  <email type="md5">88071e6e43bfa8cdedf09199c9a4736e</email>
                  <email type="domain">lip6.fr</email>
                  <idno type="idhal" notation="string">aouadjaout</idno>
                  <idno type="idhal" notation="numeric">9404</idno>
                  <idno type="halauthorid" notation="string">40114-9404</idno>
                  <idno type="ORCID">https://orcid.org/0000-0001-7248-5914</idno>
                  <idno type="IDREF">https://www.idref.fr/253126290</idno>
                  <affiliation ref="#struct-391379"/>
                </author>
                <author role="aut">
                  <persName>
                    <forename type="first">Abdelouahid</forename>
                    <surname>Derhab</surname>
                  </persName>
                  <idno type="idhal" notation="numeric">777859</idno>
                  <idno type="halauthorid" notation="string">1023508-777859</idno>
                  <idno type="ORCID">https://orcid.org/0000-0002-6498-1528</idno>
                  <affiliation ref="#struct-456208"/>
                </author>
                <author role="aut">
                  <persName>
                    <forename type="first">Nadjib</forename>
                    <surname>Badache</surname>
                  </persName>
                  <idno type="halauthorid">235503-0</idno>
                  <affiliation ref="#struct-92874"/>
                  <affiliation ref="#struct-139441"/>
                </author>
              </analytic>
              <monogr>
                <meeting>
                  <title>CODASPY</title>
                  <date type="start">2017-03-22</date>
                  <settlement>Scottsdale, Arizona</settlement>
                  <country key="US">United States</country>
                </meeting>
                <respStmt>
                  <resp>conferenceOrganizer</resp>
                  <name>ACM</name>
                </respStmt>
                <imprint>
                  <date type="datePub">2017-03-22</date>
                </imprint>
              </monogr>
              <idno type="doi">10.1145/3029806.3029838</idno>
            </biblStruct>
          </sourceDesc>
          <profileDesc>
            <langUsage>
              <language ident="en">English</language>
            </langUsage>
            <textClass>
              <classCode scheme="halDomain" n="info.info-pl">Computer Science [cs]/Programming Languages [cs.PL]</classCode>
              <classCode scheme="halTypology" n="POSTER">Conference poster</classCode>
              <classCode scheme="halOldTypology" n="POSTER">Conference poster</classCode>
              <classCode scheme="halTreeTypology" n="POSTER">Conference poster</classCode>
            </textClass>
            <abstract xml:lang="en">
              <p>Web applications use authentication mechanisms to provide user-friendly content to users. However, some dangerous techniques like session fixation attacks target these mechanisms, by making the legitimate user use a session identifier that is controlled by the attacker. In this way, he can then impersonate the legitimate user without the need to know his credentials. In this paper, we present SAWFIX, a PHP static analyzer that checks web applications for session fixation vulnerabilities. To the best of our knowledge, SAWFIX is the first analyzer that checks exhaustively for this type of vulnerabilities, while the other methods only ensure partial correctness that is limited to a fraction of possible executions. SAWFIX is based on abstract interpretation, which is a theory for approximating the semantics of programs and allows designing static analyzers that are fully automatic and sound by construction. We implemented a prototype of our approach and tested it on several complex web applications. We obtained promising results in terms of detection accuracy and processing time, which reflects the efficiency of our system.</p>
            </abstract>
          </profileDesc>
        </biblFull>
      </listBibl>
    </body>
    <back>
      <listOrg type="structures">
        <org type="laboratory" xml:id="struct-139441" status="VALID">
          <orgName>Centre de recherche sur l'Information Scientifique et Technique</orgName>
          <orgName type="acronym">CERIST</orgName>
          <desc>
            <address>
              <addrLine>5 rue des trois frères Aissou Ben Aknoun Alger</addrLine>
              <country key="DZ"/>
            </address>
            <ref type="url">http://www.cerist.dz/</ref>
          </desc>
          <listRelation>
            <relation active="#struct-301855" type="direct"/>
          </listRelation>
        </org>
        <org type="researchteam" xml:id="struct-391379" status="OLD">
          <orgName>Algorithmes, Programmes et Résolution</orgName>
          <orgName type="acronym">APR</orgName>
          <date type="start">2008-10-01</date>
          <date type="end">2017-12-31</date>
          <desc>
            <address>
              <country key="FR"/>
            </address>
          </desc>
          <listRelation>
            <relation active="#struct-233" type="direct"/>
            <relation active="#struct-93591" type="indirect"/>
            <relation name="UMR7606" active="#struct-441569" type="indirect"/>
          </listRelation>
        </org>
        <org type="laboratory" xml:id="struct-456208" status="INCOMING">
          <orgName>Center of Excellence in Information Assurance</orgName>
          <orgName type="acronym">CoEIA</orgName>
          <desc>
            <address>
              <country key="SA"/>
            </address>
          </desc>
          <listRelation>
            <relation active="#struct-302265" type="direct"/>
          </listRelation>
        </org>
        <org type="institution" xml:id="struct-92874" status="VALID">
          <orgName>Université des Sciences et de la Technologie Houari Boumediene = University of Sciences and Technology Houari Boumediene [Alger]</orgName>
          <orgName type="acronym">USTHB</orgName>
          <desc>
            <address>
              <addrLine>BP 32 EL Alia 16111 Bab Ezzouar,  Alger</addrLine>
              <country key="DZ"/>
            </address>
            <ref type="url">http://www.usthb.dz/</ref>
          </desc>
        </org>
        <org type="institution" xml:id="struct-301855" status="VALID">
          <orgName>Ministère de l'Education nationale, de l’Enseignement supérieur et de la Recherche</orgName>
          <orgName type="acronym">M.E.N.E.S.R.</orgName>
          <desc>
            <address>
              <addrLine>1 rue Descartes - 75231 Paris cedex 05</addrLine>
              <country key="FR"/>
            </address>
          </desc>
        </org>
        <org type="laboratory" xml:id="struct-233" status="OLD">
          <idno type="RNSR">199712651U</idno>
          <idno type="ROR">https://ror.org/05krcen59</idno>
          <orgName>Laboratoire d'Informatique de Paris 6</orgName>
          <orgName type="acronym">LIP6</orgName>
          <date type="start">1997-01-01</date>
          <date type="end">2017-12-31</date>
          <desc>
            <address>
              <addrLine>4 Place JUSSIEU 75252 PARIS CEDEX 05</addrLine>
              <country key="FR"/>
            </address>
            <ref type="url">http://www.lip6.fr/</ref>
          </desc>
          <listRelation>
            <relation active="#struct-93591" type="direct"/>
            <relation name="UMR7606" active="#struct-441569" type="direct"/>
          </listRelation>
        </org>
        <org type="institution" xml:id="struct-93591" status="OLD">
          <idno type="ROR">https://ror.org/02en5vm52</idno>
          <orgName>Université Pierre et Marie Curie - Paris 6</orgName>
          <orgName type="acronym">UPMC</orgName>
          <date type="end">2017-12-31</date>
          <desc>
            <address>
              <addrLine>4 place Jussieu - 75005 Paris</addrLine>
              <country key="FR"/>
            </address>
            <ref type="url">http://www.upmc.fr/</ref>
          </desc>
        </org>
        <org type="regroupinstitution" xml:id="struct-441569" status="VALID">
          <idno type="IdRef">02636817X</idno>
          <idno type="ISNI">0000000122597504</idno>
          <idno type="ROR">https://ror.org/02feahw73</idno>
          <orgName>Centre National de la Recherche Scientifique</orgName>
          <orgName type="acronym">CNRS</orgName>
          <date type="start">1939-10-19</date>
          <desc>
            <address>
              <country key="FR"/>
            </address>
            <ref type="url">https://www.cnrs.fr/</ref>
          </desc>
        </org>
        <org type="institution" xml:id="struct-302265" status="VALID">
          <idno type="ROR">https://ror.org/02f81g417</idno>
          <orgName>King Saud University [Riyadh]</orgName>
          <orgName type="acronym">KSU</orgName>
          <desc>
            <address>
              <addrLine>King Saud University, Riyadh 12372</addrLine>
              <country key="SA"/>
            </address>
            <ref type="url">http://ksu.edu.sa/en/</ref>
          </desc>
        </org>
      </listOrg>
    </back>
  </text>
</TEI>