发明名称 |
Global Variable Security Analysis |
摘要 |
A method includes determining selected global variables in a program for which flow of the selected global variables through the program is to be tracked. The selected global variables are less than all the global variables in the program. The method includes using a static analysis performed on the program, tracking flow through the program for the selected global variables. In response to one or more of the selected global variables being used in security-sensitive operations in the flow, use is analyzed of each one of the selected global variables in a corresponding security-sensitive operation. In response to a determination the use may be a potential security violation, the potential security violation is reported. Apparatus and computer program products are also disclosed. |
申请公布号 |
US2012131670(A1) |
申请公布日期 |
2012.05.24 |
申请号 |
US20100951435 |
申请日期 |
2010.11.22 |
申请人 |
ARTZI SHAY;BERG RYAN;PEYTON JOHN;PISTOIA MARCO;SRIDHARAN MANU;TATEISHI TAKAAKI;TRIPP OMER;WIENER ROBERT;INTERNATIONAL BUSINESS MACHINES CORPORATION |
发明人 |
ARTZI SHAY;BERG RYAN;PEYTON JOHN;PISTOIA MARCO;SRIDHARAN MANU;TATEISHI TAKAAKI;TRIPP OMER;WIENER ROBERT |
分类号 |
G06F21/00 |
主分类号 |
G06F21/00 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|