首页> 外文会议>World Congress on Software Engineering >Research on XML Based Static Software Security Analysis
【24h】

Research on XML Based Static Software Security Analysis

机译:基于XML的静态软件安全分析研究

获取原文

摘要

Fatal security vulnerabilities are caused by undefined behaviors of C/C++ language used in Safety-Critical software design. Software static analysis is an important technique for identifying security vulnerabilities from software code and structure. The method of static analysis based on XML intermediate model is proposed in term of safety rules. The source code is interpreted as XML intermediate model, while safety rules are translated into vulnerabilities pattern, and Xquery expression is used to locate security vulnerabilities by this method. The experimental result of a prototype system based on this method shows that this method can effectively detect the software vulnerabilities in violation of safety rules and has the advantage of supporting customization of safety rules.
机译:致命的安全漏洞是由在安全关键软件设计中使用的C / C ++语言的未定义行为引起的。软件静态分析是从软件代码和结构识别安全漏洞的重要技术。基于XML中间模型的静态分析方法在安全规则期间提出。源代码被解释为XML中间模型,而安全规则将转换为漏洞模式,并且XQuery表达式用于通过此方法定位安全漏洞。基于该方法的原型系统的实验结果表明,该方法可以有效地检测违反安全规则的软件漏洞,并具有支持定制安全规则的优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号