【24h】

Hybrid Taint Flow Analysis in Scala

机译:Scala中的混合污染流分析

获取原文

摘要

Scala is an object-oriented and functional programming language, which has taken the developers community by storm. Also, given its multi-threading/multi-processing capabilities, Scala is widely used for developing enterprise applications. However, many programmers do not perform careful security code review due to the high cost of vulnerability testing or the lack of knowledge about security issues in the Scala ecosystem. Thus, this problem often results in publishing vulnerable and unstable applications in the market. In this paper we propose TainTagger, as an innovative approach that integrates static and dynamic analysis to diagnose vulnerabilities and zero-day attacks in Scala applications. We evaluated TainTagger from two perspectives: effectiveness and performance. Our results prove the advantage of our approach in comparison with related work.
机译:Scala是一种面向对象的功能性编程语言,它已席卷开发人员社区。同样,鉴于其具有多线程/多处理功能,Scala被广泛用于开发企业应用程序。但是,由于漏洞测试的成本高昂或缺乏对Scala生态系统中安全问题的了解,许多程序员并未执行仔细的安全代码审查。因此,此问题通常导致在市场上发布易受攻击且不稳定的应用程序。在本文中,我们提出TainTagger,这是一种将静态和动态分析集成在一起以诊断Scala应用程序中的漏洞和零时差攻击的创新方法。我们从两个角度评估了TainTagger:有效性和性能。与相关工作相比,我们的结果证明了我们的方法的优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号