首页> 外文期刊>International Journal of Security and Networks >Sensitive information leakage analysis of database code by abstract interpretation
【24h】

Sensitive information leakage analysis of database code by abstract interpretation

机译:基于抽象解释的数据库代码敏感信息泄露分析

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

An information system stores outside data in the backend database to process them efficiently and protects sensitive data from illegitimate flow or unauthorised users. However, most information systems are made in such a way that the sensitive information stored in a database may be leaked explicitly or implicitly during data processing along with the control structure of the program to the output channels. Therefore, sensitive data leakage is one of the crucial security threat. In this paper, the main objective is to detect the illegitimate flow of confidential information in an information system. We propose a framework to detect sensitive information leakage through the data-flow paths of an information system. In particular, to compute the precise set of data-flow paths, we use the non-relational abstract property of the interval domain and the relational abstract property of the polyhedra domain that enables the framework to produce efficient security analysis results.
机译:信息系统将外部数据存储在后端数据库中,以有效地处理它们,并保护敏感数据免受非法流动或未经授权的用户的侵害。然而,大多数信息系统的制造方式是,存储在数据库中的敏感信息可能会在数据处理过程中与程序的控制结构一起被明确或隐式地泄露到输出通道。因此,敏感数据泄露是重要的安全威胁之一。本文的主要目的是检测信息系统中机密信息的非法流动。我们提出了一个框架来检测通过信息系统的数据流路径泄露的敏感信息。特别是,为了计算精确的数据流路径集,我们使用了区间域的非关系抽象属性和多面体域的关系抽象属性,使框架能够产生有效的安全分析结果。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号