【24h】

Hybrid Taint Flow Analysis in Scala

机译:Scala中的杂交Taint流程分析

获取原文

摘要

Scala is an object-oriented and functional programming language, which has taken the developers community by storm. Also, given its multi-threading/multi-processing capabilities, Scala is widely used for developing enterprise applications. However, many programmers do not perform careful security code review due to the high cost of vulnerability testing or the lack of knowledge about security issues in the Scala ecosystem. Thus, this problem often results in publishing vulnerable and unstable applications in the market. In this paper we propose TainTagger, as an innovative approach that integrates static and dynamic analysis to diagnose vulnerabilities and zero-day attacks in Scala applications. We evaluated TainTagger from two perspectives: effectiveness and performance. Our results prove the advantage of our approach in comparison with related work.
机译:Scala是一种面向对象和功能的编程语言,它曾通过风暴拍摄开发人员社区。另外,考虑到其多线程/多处理能力,Scala广泛用于开发企业应用程序。然而,由于漏洞测试的高成本或缺乏关于Scala生态系统中的安全问题的知识,许多程序员不会对仔细的安全码​​审查进行仔细安全码。因此,这个问题往往会导致在市场上发布易受伤害和不稳定的应用。在本文中,我们提出了一种创新的方法,作为一种创新的方法,可以集成静态和动态分析,以诊断Scala应用程序中的漏洞和零日攻击。我们从两个视角评估了Taintage:有效性和性能。我们的结果证明了我们与相关工作相比的方法的优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号