发明名称 Runtime enforcement of security checks
摘要 A method is disclosed that includes tracking untrusted inputs through an executing program into a sink, the tracking including maintaining context of the sink as strings based on the untrusted inputs flow into the sink. The method also includes, while tracking, in response to a string based on an untrusted input being about to flow into the sink and a determination the string could lead to an attack if the string flows into a current context of the sink, endorsing the string using an endorser selected based at least on the current context of the sink, and providing the endorsed string to the sink. Computer program products and apparatus are also disclosed.
申请公布号 US8646088(B2) 申请公布日期 2014.02.04
申请号 US20110983407 申请日期 2011.01.03
申请人 PISTOIA MARCO;TRIPP OMER;VECHEV MARTIN;YAHAV ERAN;INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 PISTOIA MARCO;TRIPP OMER;VECHEV MARTIN;YAHAV ERAN
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址