首页> 外国专利> Using code similarities for improving auditing and fixing of SAST-discovered code vulnerabilities

Using code similarities for improving auditing and fixing of SAST-discovered code vulnerabilities

机译:使用代码相似性来改进审核和修复SAST发现的代码漏洞

摘要

Implementations of the present disclosure include methods, systems, and computer-readable storage mediums for receiving results from security testing of source code, each result indicating a potential security vulnerability of the source code, displaying graphical representations of the results to a user, and, by a fix recommendation generator: receiving user input indicating a result of the results, receiving a set of code clones, each code clone being provided based on at least a snippet of the source code underlying the result, receiving a set of repairs, each repair being associated with a code clone, and mitigating a previously determined security vulnerability, and providing a set of fix recommendations based on the set of code clones, the set of repairs, and similarity metrics, each similarity metric indicating a similarity between the at least a snippet of the source code and a respective code clone.
机译:本公开的实现包括用于从源代码的安全性测试接收结果的方法,系统和计算机可读存储介质,每个结果指示源代码的潜在安全性漏洞,向用户显示结果的图形表示,以及通过修订建议生成器:接收指示结果结果的用户输入,接收一组代码克隆,每个代码克隆至少基于作为结果基础的源代码片段提供,接收一组修复,每次修复与代码克隆相关联,并减轻先前确定的安全漏洞,并基于代码克隆集,修复程序集和相似性度量提供一组修复建议,每个相似性度量指示至少一个之间的相似性。源代码的片段以及相应的代码克隆。

著录项

  • 公开/公告号US9965633B2

    专利类型

  • 公开/公告日2018-05-08

    原文格式PDF

  • 申请/专利权人 SAP SE;

    申请/专利号US201514982309

  • 发明设计人 MICHAEL HERZBERG;ACHIM D. BRUCKER;

    申请日2015-12-29

  • 分类号G06F21/00;G06F21/57;G06F21/55;H04L29/06;G06F21/56;

  • 国家 US

  • 入库时间 2022-08-21 12:55:14

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号