5Su Zhendong, Wassermann G. The essence of command injection attacks in Web applications [C] //Proc of the ACM Symp on PrincipLes of Programming Languages (POPL). New York: ACM, 2006.
6Kneuss E, Suter P, Kuncak V. Phantm: Php analyzer for type mismatch [C] //Proc of ACM SIGSOFT 18th Int Symp on the Foundations of Software Engineering. New York: ACM, 2010.
7Jovanovic N, Kruegel C, Kirda E. Precise alias analysis for static detection of Web application vulnerabilities [C] //Proc of ACM SIGPLAN Workshop on Programming Languages and Analysis for Security. New York: ACM, 2006.
8Minamide Y. Static approximation of dynamically generated Web pages [C] //Proc of the 14th Int Conf on World Wide Web. NewYork: ACM, 2005.
9Wassermann G, Su Zhendong. Sound and precise analysis of Web applications for injection vulnerabilities [C]//Proc of ACM Conf on Programming Language Design and Implementation (PLDI). New York: ACM, 2007.
10Wassermann G, Su Zhendong. Static detection of cross-site scripting vulnerabilities [C] //Proc of the 29th Int Conf on Software Engineering(ICSE). New York: ACM, 2008.