首页> 外文会议>2011 Seventh International Conference on Mobile Ad-hoc and Sensor Networks >Towards a Flaw Function Heuristic Vulnerability Static Analysis Framework for Executable File
【24h】

Towards a Flaw Function Heuristic Vulnerability Static Analysis Framework for Executable File

机译:面向可执行文件的缺陷函数启发式漏洞静态分析框架

获取原文

摘要

The misuse of flaw functions is one of the key reasons causing software vulnerabilites. In our study, this type of vulnerability is termed as MFFV (Vulnerability of Flaw Function Misusing). In this paper, we propose a novel framework for analyzing the flaw function heuristic vulnerabilities. In this framework, the procedure to analyze MFFV is composed of three stages: firstly, MFFV pre-analysis engine builds the intermediate representation via reverse engineering technique, and meanwhile the flaw functions are identified according to the function signature technology. Secondly, MFFV analysis engine picks up the suspicious hot points, and attaches a label to each of them. The label records the code slice, flaw function information and context. In the third stage, MFFV scheduler invokes a series of related checkers to perform precise checks on all the hot points. Besides, we implement a prototype to verify the feasibility of our proposed framework.
机译:缺陷功能的滥用是引起软件漏洞的关键原因之一。在我们的研究中,这种类型的漏洞称为MFFV(缺陷功能滥用的漏洞)。在本文中,我们提出了一个用于分析缺陷函数启发式漏洞的新颖框架。在此框架下,MFFV的分析过程包括三个阶段:首先,MFFV预分析引擎通过逆向工程技术构建中间表示,然后根据功能签名技术识别缺陷功能。其次,MFFV分析引擎提取可疑热点,并在每个热点上附加标签。标签记录代码片段,缺陷功能信息和上下文。在第三阶段,MFFV调度程序调用一系列相关的检查程序以对所有热点执行精确的检查。此外,我们实施了一个原型来验证我们提出的框架的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号