首页> 外文会议>IEEE Symposium on Security and Privacy >An Automated Approach for Identifying Potential Vulnerabilities in Software
【24h】

An Automated Approach for Identifying Potential Vulnerabilities in Software

机译:一种识别软件潜在漏洞的自动方法

获取原文
获取外文期刊封面目录资料

摘要

This paper presents results from analyzing the vulnerability of security-critical software applications to malicious threats and anomalous events using an automated fault injection analysis approach. The work is based on the well-understood premise that a large proportion of security violations result from errors in software source code and configuration. The methodology employs software fault injection to force anomalous program states during the execution of software and observes their corresponding effects on system security. If insecure behavior is detected, the perturbed location that resulted in the violation is isolated for further analysis and possibly retrofitting with fault-tolerant mechanisms.
机译:本文提出了使用自动故障注入分析​​方法分析安全关键软件应用程序对恶意威胁和异常事件的脆弱性的结果。这项工作基于良好的良好的前提,即大部分安全违规是由软件源代码和配置中的错误产生的。该方法采用软件故障注入,在执行软件期间强制异常程序状态,并观察它们对系统安全的相应影响。如果检测到不安全行为,则将导致违规的扰动位置被隔离进行进一步的分析,并且可能以容错机制改装。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号