首页> 外国专利> VULNERABILITY DISCOVERING DEVICE, VULNERABILITY DISCOVERING METHOD, AND VULNERABILITY DISCOVERING PROGRAM

VULNERABILITY DISCOVERING DEVICE, VULNERABILITY DISCOVERING METHOD, AND VULNERABILITY DISCOVERING PROGRAM

机译:漏洞发现装置,漏洞发现方法和漏洞发现程序

摘要

A vulnerability detection device (10) includes a vulnerability portion extracting unit (13) that extracts a first program code corresponding to an uncorrected vulnerability portion of software, a normalization processing unit (14) that normalizes a parameter varying depending on compilation environment, among parameters included in the extracted first program code and in a second program code of software as a target to be tested for the vulnerability portion, a similarity calculating unit (15) that calculates a similarity of an arbitrary portion of the second program code after normalization as a comparison target to the first program code, and a determining unit (16) that refers to vulnerability related information for a portion of the second program code in which the calculated first similarity exceeds a predetermined threshold, and that determines whether the portion of the second program code is an unknown vulnerability portion.
机译:漏洞检测设备(10)包括:漏洞部分提取单元(13),其提取与软件的未校正漏洞部分相对应的第一程序代码;归一化处理单元(14),其对参数中根据编译环境而变化的参数进行归一化相似度计算单元(15)包括在所提取的第一程序代码和软件的第二程序代码中,作为要针对脆弱性部分进行测试的目标,该相似度计算单元(15)将归一化后的第二程序代码的任意部分的相似度计算为第一程序代码的比较目标,以及确定单元(16),该单元参考第二程序代码的一部分的脆弱性相关信息,其中计算出的第一相似度超过预定阈值,并确定第二程序的该部分是否代码是未知漏洞部分。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号