首页> 外文期刊>Cogent Engineering >Stacy-static code analysis for enhanced vulnerability detection
【24h】

Stacy-static code analysis for enhanced vulnerability detection

机译:静态静态代码分析可增强漏洞检测能力

获取原文
获取外文期刊封面目录资料

摘要

AbstractComputer program analysis refers to the automatic analysis of the behavior of a user defined program. An application of program analysis is to determine the quality of source code. Humans are prone to errors and, in most cases, the penalty of deploying low quality code is very high for a large organization. These errors often give rise to potential security vulnerabilities in an application, which could be exploited by malicious users. In this paper, we present Stacy—a tool that statically detects potential security vulnerabilities present in input source code. Static program analysis is the examination of source code prior to its execution. Our tool attempts to predict the behavior of a program before it is deployed. Stacy uses novel techniques to detect the primary sources of vulnerability in the source code of a program and informs the developer.
机译:计算机程序分析是指对用户定义程序的行为进行自动分析。程序分析的一种应用是确定源代码的质量。人类容易出错,在大多数情况下,对于大型组织而言,部署低质量代码的代价非常高。这些错误通常会导致应用程序中潜在的安全漏洞,恶意用户可能会利用这些漏洞。在本文中,我们介绍了Stacy-一种静态检测输入源代码中存在的潜在安全漏洞的工具。静态程序分析是在执行源代码之前对其进行检查。我们的工具尝试在程序部署之前预测其行为。 Stacy使用新颖的技术来检测程序源代码中的主要漏洞来源,并通知开发人员。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号