发明名称
摘要 PROBLEM TO BE SOLVED: To detect only a location at which a vulnerable library is not appropriately used. SOLUTION: A storage part stores a previously defined determination rule for vulnerability, in which a function name and the position of an argument of the function are associated with each other, the argument having possibility to be set by a wrong value. A vulnerability audit method reads in the determination rule from the storage part; parses a program to be checked; extracts a variable whose value is externally input in the parsed program to be checked and traces the variable according to a processing flow; determines, when the traced variable is used in a location of the function and the argument of the function, which are defined in the determination rule (Y in S32), whether the variable is used in a conditional expression including a comparison operator; and when determined to be not, generates an alert message and outputs the message on a screen or a file (S44). COPYRIGHT: (C)2011,JPO&INPIT
申请公布号 JP5077455(B2) 申请公布日期 2012.11.21
申请号 JP20110048514 申请日期 2011.03.07
申请人 发明人
分类号 G06F21/22 主分类号 G06F21/22
代理机构 代理人
主权项
地址