首页> 外文期刊>Electronic Communications of the EASST >Static Analysis of Information Release in Interactive Programs
【24h】

Static Analysis of Information Release in Interactive Programs

机译:交互式程序中信息发布的静态分析

获取原文
           

摘要

In this paper we present a model for analysing information release (or leakage) in programs written in a simple imperative language. We present the se- mantics of the language, an attacker model, and the notion of an information release policy. Our key contribution is the static analysis technique to compute information release of programs and to verify it against a policy. We demonstrate our approach by analysing information released to an attacker by faulty password checking pro- grams; our example is inspired by a known flaw in versions of OpenSSH distributed with various Unix, Linux, and OpenBSD operating systems.
机译:在本文中,我们提出了一种用于分析以简单命令式语言编写的程序中的信息释放(或泄漏)的模型。我们介绍了语言的语义,攻击者模型以及信息发布策略的概念。我们的主要贡献是静态分析技术,用于计算程序的信息发布并根据策略进行验证。我们通过分析错误的密码检查程序释放给攻击者的信息来证明我们的方法。我们的示例的灵感来自与各种Unix,Linux和OpenBSD操作系统一起发行的OpenSSH版本中的已知缺陷。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号