发明名称 System, Method And Apparatus To Visually Configure An Analysis Of A Program
摘要 A method extracts views from an application program, where at least some extracted views include at least one view component, and presenting the extracted views to a user. In response to the user selecting a view component in a presented extracted view, the method presents a form to the user having a plurality of vulnerability types indicated for the selected view component and, for each vulnerability type, provides an ability for the user to set an indicator in the form as to indicate whether the view component is at least one of a source or a sink. The method further includes saving the form containing the user's input in conjunction with a user-provided label for the selected view component and a unique identification of the selected view component, and deriving an analysis policy configuration from the saved form that is formatted for use by a program security analyzer.
申请公布号 US2016344761(A1) 申请公布日期 2016.11.24
申请号 US201615226999 申请日期 2016.08.03
申请人 International Business Machines Corporation 发明人 Ligman Joseph W.;Pistoia Marco;Tripp Omer
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method, comprising: extracting views from an application program, where at least some extracted views comprise at least one view component, the at least one view component comprising an application-specific screenshot of a user-interface content and layout; presenting the extracted views to a user; in response to the user selecting a view component in a presented extracted view, presenting a form to the user having a plurality of vulnerability types indicated for the selected view component and, for each vulnerability type, providing an ability for the user to set an indicator in the form to indicate whether the view component is at least one of a source or a sink; saving the form containing the user's input in conjunction with a user-provided label for the selected view component and a unique identification of the selected view component; and deriving an analysis policy configuration from the saved form that is formatted for use by a program security analyzer.
地址 Armonk NY US
您可能感兴趣的专利