发明名称 Generating Sound and Minimal Security Reports Based on Static Analysis of a Program
摘要 A method is disclosed that includes, using a static analysis, analyzing a software program to determine a number of paths from sources accepting information to sinks using that information or a modified version of that information and to determine multiple paths from the number of paths. The determined multiple paths have a same transition from an application portion of the software program to a library portion of the software program and require a same downgrading action to address a vulnerability associated with source-sink pairs in the multiple paths. The analyzing includes determining the multiple paths using a path-sensitive analysis. The method includes, for the determined multiple paths, grouping the determined multiple paths into a single representative indication of the determined multiple paths. The method includes outputting the single representative indication. Computer program products and apparatus are also disclosed.
申请公布号 US2012216177(A1) 申请公布日期 2012.08.23
申请号 US201113033024 申请日期 2011.02.23
申请人 FINK STEPHEN;HAVIV YINNON A.;PISTOIA MARCO;TRIPP OMER;WEISMAN OMRI;INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 FINK STEPHEN;HAVIV YINNON A.;PISTOIA MARCO;TRIPP OMER;WEISMAN OMRI
分类号 G06F9/44 主分类号 G06F9/44
代理机构 代理人
主权项
地址