首页> 外文会议>IEEE Annual Computer Software and Applications Conference >Randomness Classes in Bugs Framework (BF): True-Random Number Bugs (TRN) and Pseudo-Random Number Bugs (PRN)
【24h】

Randomness Classes in Bugs Framework (BF): True-Random Number Bugs (TRN) and Pseudo-Random Number Bugs (PRN)

机译:错误框架中的随机性类(bf):真正随机数bug(trn)和伪随机数bug(prn)

获取原文

摘要

Random number generators may have weaknesses (bugs) and the applications using them may become vulnerable to attacks. Formalization of randomness bugs would help researchers and practitioners identify them and avoid security failures. The Bugs Framework (BF) comprises rigorous definitions and (static) attributes of bug classes, along with their related dynamic properties, such as proximate and secondary causes, consequences and sites. This paper presents two new BF classes: True-Random Number Bugs (TRN) and Pseudo-Random Number Bugs (PRN). We analyze particular vulnerabilities and use these classes to provide clear BF descriptions. Finally, we discuss the lessons learned towards creating new BF classes.
机译:随机数生成器可能具有弱点(错误),并且使用它们的应用可能变得容易攻击。随机性错误的形式化将有助于研究人员和从业者识别它们并避免安全失败。错误框架(BF)包括错误类的严格定义和(静态)属性,以及它们相关的动态属性,例如近似和次要原因,后果和站点。本文呈现了两个新的BF类:真正随机数错误(TRN)和伪随机数错误(PRN)。我们分析了特定的漏洞,并使用这些类来提供明确的BF描述。最后,我们讨论了创建新的BF课程的经验教训。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号