发明名称 Answering Security Queries Statically Based On Dynamically-Determined Information
摘要 A method includes analyzing execution of a software program, the software program having sources returning values, sinks that perform security-sensitive operations on those returned values or modified versions of the returned values, and flows of the returned values to the sinks, the analyzing determining a first set of methods having access to a value returned from a selected one of the sources. A static analysis is performed on the software program, the static analysis using the first set of methods to determine a second set of methods having calling relationships with the selected source, the static analysis determining whether the returned value from the selected source can flow through a flow to a sink that performs a security-sensitive operation without the flow to the sink being endorsed, and in response, indicating a security violation. Apparatus and computer program products are also disclosed.
申请公布号 US2012144491(A1) 申请公布日期 2012.06.07
申请号 US20100957529 申请日期 2010.12.01
申请人 PISTOIA MARCO;TRIPP OMER;INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 PISTOIA MARCO;TRIPP OMER
分类号 G06F21/00;G06F9/44 主分类号 G06F21/00
代理机构 代理人
主权项
地址