首页> 外文会议>Global security, safety, and sustainability >Static and Dynamic Analysis for Web Security in Generic Format
【24h】

Static and Dynamic Analysis for Web Security in Generic Format

机译:通用格式的Web安全静态和动态分析

获取原文
获取原文并翻译 | 示例

摘要

Further to the milestone we achieved in flagging and logging by using generic abstract syntax format, we applied metadata messaging to identify individual node. In order to explore the concept of generic format, we are currently investigating security automaton, event based trigger, and their interference by means of node identification and state transfer. Our objective in web security is to move black box to white box in enterprise practices. In this paper, we explain how our approaches achieve the goal in terms of static and dynamic analysis. To better explain the framework and roadmap of analysis work, we describe our approaches by using macro and micro views individually. Macro view covers analysis of the abstract syntax structure and block identification are the key in flow tracking. Micro view includes node to node interference, the metadata messaging, security automaton we applied, and interoperability between event and node. The logging outputs produced by static analysis can be further developed for dynamic analysis. This bridge the static and dynamic analysis by using tracking and validation techniques. This can also build up the foundation of the web security governance.
机译:通过使用通用抽象语法格式在标记和日志记录方面实现的里程碑之外,我们还应用了元数据消息传递来标识单个节点。为了探索通用格式的概念,我们目前正在研究安全性自动机,基于事件的触发器及其通过节点标识和状态转移的干扰。我们在网络安全方面的目标是在企业实践中将黑盒子迁移到白盒子。在本文中,我们从静态和动态分析的角度解释了我们的方法如何实现目标。为了更好地解释分析工作的框架和路线图,我们通过分别使用宏观和微观视图来描述我们的方法。宏视图涵盖了对抽象语法结构的分析,并且块标识是流跟踪中的关键。微观视图包括节点到节点的干扰,元数据消息传递,我们应用的安全性自动机以及事件与节点之间的互操作性。静态分析产生的测井输出可以进一步开发用于动态分析。通过使用跟踪和验证技术,这架了静态和动态分析的桥梁。这也可以建立Web安全治理的基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号