首页> 外文会议>International Conference on Information and Communications Security >Ontology Model-Based Static Analysis of Security Vulnerabilities
【24h】

Ontology Model-Based Static Analysis of Security Vulnerabilities

机译:基于本体模型的安全漏洞静态分析

获取原文

摘要

Static analysis technologies and tools have been widely adopted in detecting software bugs and vulnerabilities. However, traditional approaches have their limitations on extensibility and reusability due to their methodologies, and are unsuitable to describe subtle vulnerabilities under complex and unaccountable contexts. This paper proposes an approach of static analysis based on ontology model enhanced by program slicing technology for detecting software vulnerabilities. We use Ontology Web Language (OWL) to model the source code and Semantic Web Rule Language (SWRL) to describe the bug and vulnerability patterns. Program slicing criteria can be automatically extracted from the SWRL rules and adopted to slice the source code. A prototype of security vulnerability detection (SVD) tool is developed to show the validity of the proposed approach.
机译:检测软件错误和漏洞中已广泛采用静态分析技术和工具。然而,传统方法具有局限性,由于其方法,不适用,并且不适合在复杂和不负责任的背景下描述微妙的漏洞。本文提出了一种基于本体模型的静态分析方法,通过编程切片技术来检测软件漏洞。我们使用本体网络语言(OWL)来模拟源代码和语义Web规则语言(SWRL)来描述错误和漏洞模式。程序切片标准可以自动从SWRL规则中提取并采用以切片源代码。开发了安全漏洞检测(SVD)工具的原型以显示所提出的方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号