首页> 外文会议>International Conference on Applications of Digital Information and Web Technologies >An Approach to Tracing Information Flows of Untrustworthy Data in Programs
【24h】

An Approach to Tracing Information Flows of Untrustworthy Data in Programs

机译:追踪课程中不值得信任数据的信息流的方法

获取原文
获取外文期刊封面目录资料

摘要

As the role of software increases in computing environments, issues in software security become more important problems. Taint analysis is a technique to trace and manage tainted data originated from untrustworthy sources in a program. This analysis can be applied to software security verification as well as software behavior understanding, testing unexpected errors, or debugging. In this paper, we present a method for tracing information flows of untrustworthy data in a base language. In addition, we verify the correctness of the proposed algorithm by implementing an analyzer, and show that propagation of untrustworthy data can be traced by the proposed algorithm. The proposed trace algorithm can be applied to understand the analysis procedures of information flows of untrustworthy data, and it can be used in software analysis to detect security problems that is caused by misuse of information in software or system.
机译:随着软件在计算环境中增加的作用,软件安全性的问题变得更加重要。 Taint分析是一种追踪和管理源自课程中不值得信任来源的污染数据的技术。该分析可以应用于软件安全验证以及软件行为理解,测试意外错误或调试。在本文中,我们介绍了一种在基本语言中跟踪信息流的信息流程。此外,我们通过实现分析仪验证所提出的算法的正确性,并显示不值得信赖的数据的传播可以通过所提出的算法进行跟踪。可以应用所提出的轨迹算法来了解不值得信任数据的信息流的分析程序,并且可以用于软件分析以检测由软件或系统中信息滥用信息引起的安全问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号