发明名称 Determining suitable insertion points for string sanitizers in a computer code
摘要 A method of determining suitable insertion points for inserting string sanitizers in a computer code is provided herein. The method includes the following stages: obtaining: (i) a computer code associated with a data flow of externally supplied data, from one or more sources to one or more sinks, (ii) locations of the sources, and (iii) locations of the sinks; building a graph representing control paths, data paths and semantic relationships between the control paths and the data paths of the computer code; associating all tainted data paths on the graph, being data paths that go from sources to sinks and do not include a sanitizer; and determining, on the tainted data paths, potential control paths suitable for sanitizer insertion.
申请公布号 US8539466(B2) 申请公布日期 2013.09.17
申请号 US201113113097 申请日期 2011.05.23
申请人 ABADI AHARON;BNAYAHU JONATHAN;ETTINGER RAN;FELDMAN YISHAI ABRAHAM;HAVIV YINNON AVRAHAM;SHARABANI ADI;INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 ABADI AHARON;BNAYAHU JONATHAN;ETTINGER RAN;FELDMAN YISHAI ABRAHAM;HAVIV YINNON AVRAHAM;SHARABANI ADI
分类号 G06F9/45 主分类号 G06F9/45
代理机构 代理人
主权项
地址