首页> 外国专利> OPEN-SOURCE SOFTWARE VULNERABILITY ANALYSIS

OPEN-SOURCE SOFTWARE VULNERABILITY ANALYSIS

机译:开源软件漏洞分析

摘要

To analyze open-source code at a large scale, a security domain graph language ("SGL") has been created that functions as a vulnerability description language and facilitates program analysis queries. The SGL facilitates building and maintaining a graph database to catalogue vulnerabilities found in open-source components. This vulnerability database generated with SGL is used for analysis of software projects which use open source components. An agent which interacts with the vulnerability database can perform a scan of a software project to identify open-source components used in the project and submit queries to the vulnerability database to identify vulnerabilities which may affect the open-source components in the project. Results of the scan are presented to a user in the form of a vulnerability report which indicates vulnerabilities that have been discovered and which open-source components the vulnerabilities affect.
机译:为了大规模分析开源代码,已经创建了安全域图语言(“ SGL”),该语言用作漏洞描述语言并有助于程序分析查询。 SGL有助于构建和维护图形数据库,以分类在开源组件中发现的漏洞。用SGL生成的此漏洞数据库用于分析使用开源组件的软件项目。与漏洞数据库进行交互的代理可以执行软件项目的扫描,以识别项目中使用的开源组件,并向漏洞数据库提交查询,以识别可能影响项目中的开源组件的漏洞。扫描结果以漏洞报告的形式显示给用户,该报告指示已发现的漏洞以及漏洞影响哪些开源组件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号