首页> 外文会议>IEEE International Conference on Trust, Security and Privacy in Computing and Communications >iTES: Integrated Testing and Evaluation System for Software Vulnerability Detection Methods
【24h】

iTES: Integrated Testing and Evaluation System for Software Vulnerability Detection Methods

机译:符号:软件漏洞检测方法的集成测试和评估系统

获取原文

摘要

To find software vulnerabilities using software vulnerability detection technology is an important way to ensure the system security. Existing software vulnerability detection methods have some limitations as they can only play a certain role in some specific situations. To accurately analyze and evaluate the existing vulnerability detection methods, an integrated testing and evaluation system (iTES) is designed and implemented in this paper. The main functions of the iTES are:(1) Vulnerability cases with source codes covering common vulnerability types are collected automatically to form a vulnerability cases library; (2) Fourteen methods including static and dynamic vulnerability detection are evaluated in iTES, involving the Windows and Linux platforms; (3) Furthermore, a set of evaluation metrics is designed, including accuracy, false positive rate, utilization efficiency, time cost and resource cost. The final evaluation and test results of iTES have a good guiding significance for the selection of appropriate software vulnerability detection methods or tools according to the actual situation in practice.
机译:要使用软件漏洞检测技术查找软件漏洞是一种确保系统安全性的重要途径。现有软件漏洞检测方法具有一些限制,因为它们只能在某些特定情况下发挥某种作用。为了准确分析和评估现有的漏洞检测方法,在本文中设计和实施了集成测试和评估系统(ITES)。 ITES的主要功能是:(1)自动收集涵盖常用漏洞类型的源代码的漏洞情况,以形成漏洞案例库; (2)在涉及Windows和Linux平台的情况下评估包括静态和动态漏洞检测的十四条方法; (3)此外,设计了一组评估度量,包括精度,假阳性率,利用效率,时间成本和资源成本。根据实际情况的实际情况,选择适当的软件漏洞检测方法或工具具有良好的指导意义。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号