首页> 外文会议>International Conference on Science of Cyber Security >Knowledge Graph Based Semi-automatic Code Auditing System
【24h】

Knowledge Graph Based Semi-automatic Code Auditing System

机译:基于知识图的半自动代码审计系统

获取原文

摘要

Aiming at detecting various vulnerabilities in Web application system based on PHP language, a semi-automatic code auditing system based on knowledge graph is proposed. Firstly, the abstract syntax tree of each file in the Web application system is constructed to extract the taint variables and function information from the abstract syntax tree and construct the global variable information. Secondly, the data flow information of each taint variable is analyzed accurately. Finally, the knowledge graph and code auditing technology are combined to construct and display the vulnerability information of the Web application system in the form of graph. Experiments and analysis results show that this detection method can well construct and display the data flow information of each taint variable and help auditors find common vulnerabilities in Web application systems more quickly.
机译:旨在根据PHP语言检测Web应用系统中的各种漏洞,提出了一种基于知识图形的半自动审计系统。首先,构造Web应用系统中每个文件的抽象语法树以从抽象语法树中提取Taint变量和功能信息,并构建全局变量信息。其次,准确地分析每个Taint变量的数据流信息。最后,将知识图和代码审计技术组合以以图形的形式构建和显示Web应用系统的漏洞信息。实验和分析结果表明,该检测方法可以很好地构造并显示每个Taint变量的数据流信息,并帮助审计师更快地找到Web应用系统中的常见漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号