首页> 外文会议>IEEE/ACM International Conference on Software Engineering: Companion >Poster: Detecting Missing Checks for Identifying Insufficient Attack Protections
【24h】

Poster: Detecting Missing Checks for Identifying Insufficient Attack Protections

机译:海报:检测缺少攻击保护的检查

获取原文

摘要

Missing check for untrusted input used in security-sensitive operations is one of the major causes of various serious vulnerabilities. Thus, efficiently detecting missing checks for realistic software is essential for identify insufficient attack protections. We propose a systematic static approach to detect missing checks in C/C++ programs. An automated and cross-platform tool named Vanguard was implemented on top of Clang/LLVM 3.6.0. And experimental results have shown its effectiveness and efficiency.
机译:缺少安全敏感操作中使用的不受信任输入的检查是各种严重漏洞的主要原因之一。因此,有效地检测对现实软件的缺失检查对于识别不足的攻击保护是必不可少的。我们提出了一种系统的静态方法来检测C / C ++程序中的缺失检查。名为Vanguard的自动化和跨平台工具在Clang / LLVM 3.6.0的顶部实现。实验结果表明了其有效性和效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号