首页> 外文会议>Annual IFIP WG 11.3 conference on data and applications security and privacy >Runtime Detection of Zero-Day Vulnerability Exploits in Contemporary Software Systems
【24h】

Runtime Detection of Zero-Day Vulnerability Exploits in Contemporary Software Systems

机译:当代软件系统中零日漏洞利用的运行时检测

获取原文

摘要

It is argued that runtime verification techniques can be used to identify unknown application security vulnerabilities that are a consequence of unexpected execution paths in software. A methodology is proposed that can be used to build a model of expected application execution paths during the software development cycle. This model is used at runtime to detect exploitation of unknown security vulnerabilities using anomaly detection style techniques. The approach is evaluated by considering its effectiveness in identifying 19 vulnerabilities across 26 versions of Apache Struts over a 5 year period.
机译:有人认为,运行时验证技术可用于识别未知的应用程序安全漏洞,这些漏洞是软件中意外执行路径的结果。提出了一种方法,可用于在软件开发周期内构建预期的应用程序执行路径的模型。该模型在运行时用于使用异常检测样式技术来检测未知安全漏洞的利用。通过评估该方法在5年内可识别26个版本的Apache Struts中的19个漏洞的有效性来评估该方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号