• 查询稿件
  • 获取最新论文
  • 知晓行业信息

基于CodeQL的铁路Web应用源代码安全检测技术研究

CodeQL-based source code security detection technology for railway Web applications

  • 摘要: 铁路Web应用面临结构化查询语言(SQL)注入、文件上传等高危安全威胁,传统安全检测工具误报率高、业务逻辑漏洞覆盖不足,且合规要求动态化导致人工审计效率低下。文章研究基于CodeQL铁路Web应用安全应用源代码安全检测技术,涵盖传统漏洞的基线检查、逻辑漏洞的精确建模及合规需求的代码转化等关键技术,并提出将CodeQL集成至铁路Web应用全生命周期的方法,旨在实现安全能力与开发效能的协同提升,为铁路系统数字化转型提供有效参考。

     

    Abstract: Railway Web applications face high-risk security threats such as Structured Query Language (SQL) injection and file uploading. Traditional security detection tools have high false alarm rates, insufficient coverage of business logic vulnerabilities, and low efficiency in manual auditing due to dynamic compliance requirements. This paper studied the source code security detection technology for railway Web applications based on CodeQL, which covered key technologies such as baseline checks for traditional vulnerabilities, precise modeling of logical vulnerabilities, and code conversion for compliance requirements. It also proposed a method for integrating CodeQL into the entire lifecycle of railway Web applications, aimed to implement a synergistic improvement in security capabilities and development efficiency, and provide effective reference for the digital transformation of railway systems.

     

/

返回文章
返回