首页> 外文会议>International Conference on Software Engineering: Companion Proceedings >Mockingbird: A Framework for Enabling Targeted Dynamic Analysis of Java Programs
【24h】

Mockingbird: A Framework for Enabling Targeted Dynamic Analysis of Java Programs

机译:MockingBird:启用针对Java程序的目标动态分析的框架

获取原文

摘要

The paper presents the Mockingbird framework that combines static and dynamic analyses to yield an efficient and scalable approach to analyze large Java software. The framework is an innovative integration of existing static and dynamic analysis tools and a newly developed component called the Object Mocker that enables the integration. The static analyzers are used to extract potentially vulnerable parts from large software. Targeted dynamic analysis is used to analyze just the potentially vulnerable parts to check whether the vulnerability can actually be exploited. We present a case study to illustrate the use of the framework to analyze complex software vulnerabilities. The case study is based on a challenge application from the DARPA Space/Time Analysis for Cybersecurity (STAC) program. Interestingly, the challenge program had been hardened and was thought not to be vulnerable. Yet, using the framework we could discover an unintentional vulnerability that can be exploited for a denial of service attack. The accompanying demo video depicts the case study. Video: https://youtu.be/m9OUWtocWPE.
机译:本文介绍了静态和动态分析的模拟鸟框架,以产生高效且可扩展的方法来分析大型Java软件。该框架是现有静态和动态分析工具的创新集成以及一个名为Envite Indocker的新开发的组件,可实现集成。静态分析仪用于从大型软件中提取潜在的易受攻击的部件。目标动态分析用于分析潜在易受攻击的部分,以检查漏洞是否可以剥削。我们展示了一个案例研究,说明了框架的使用来分析复杂的软件漏洞。案例研究基于来自Cyber​​security(Stac)计划的DARPA空间/时间分析的挑战申请。有趣的是,挑战计划已被硬化,被认为不脆弱。然而,使用该框架,我们可以发现可以利用拒绝服务攻击的无意漏洞。伴随的演示视频描绘了案例研究。视频:https://youtu.be/m9ouwtocwpe。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号