发明名称 Global Variable Security Analysis
摘要 A method includes determining selected global variables in a program for which flow of the selected global variables through the program is to be tracked. The selected global variables are less than all the global variables in the program. The method includes using a static analysis performed on the program, tracking flow through the program for the selected global variables. In response to one or more of the selected global variables being used in security-sensitive operations in the flow, use is analyzed of each one of the selected global variables in a corresponding security-sensitive operation. In response to a determination the use may be a potential security violation, the potential security violation is reported. Apparatus and computer program products are also disclosed.
申请公布号 US2012131670(A1) 申请公布日期 2012.05.24
申请号 US20100951435 申请日期 2010.11.22
申请人 ARTZI SHAY;BERG RYAN;PEYTON JOHN;PISTOIA MARCO;SRIDHARAN MANU;TATEISHI TAKAAKI;TRIPP OMER;WIENER ROBERT;INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 ARTZI SHAY;BERG RYAN;PEYTON JOHN;PISTOIA MARCO;SRIDHARAN MANU;TATEISHI TAKAAKI;TRIPP OMER;WIENER ROBERT
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址