发明名称 A method and device for code audit
摘要 The present invention discloses a code audit method, comprising the steps of: tracing a variable in source codes to acquire the processing nodes that process the variable; determining the parent processing nodes of the processing nodes as well as the security attribute of the processing nodes; individually comparing the security attribute of the processing nodes and the security attribute of their parent processing nodes and, in case the security attribute of the parent processing node of a processing node is not a subset of the security attribute of the processing node, determining that there are security vulnerabilities in the processing node. In addition, the present invention further discloses a code audit device. Since the technical solution of the present invention determines whether there are any vulnerabilities in the processing nodes according to their logic for variable processing, it can improve the accuracy of the code audit and truly, accurately reflect any security vulnerabilities in the source codes.
申请公布号 EP2107484(A2) 申请公布日期 2009.10.07
申请号 EP20090155224 申请日期 2009.03.16
申请人 SIEMENS AKTIENGESELLSCHAFT 发明人 HU, JIAN JUN;SUI, AI FEN;TANG, WEN
分类号 G06F21/57;G06F11/36 主分类号 G06F21/57
代理机构 代理人
主权项
地址
您可能感兴趣的专利