首页> 外国专利> Execution of test inputs with applications in computer security assessment

Execution of test inputs with applications in computer security assessment

机译:使用计算机安全评估中的应用程序执行测试输入

摘要

A given application is instrumented to trace its execution flow. Constraints and/or transformation associated with input identified in the execution flow are mirrored on a set of candidate test payloads. The set of candidate test payloads are modified or pruned based on the execution flow of the instrumented application reaching a security operation with the input satisfying the constraints while the payloads may not. If the set of candidate test payloads is not empty at reaching the security operation, it is determined that the give application has vulnerability and a signal issuing a warning may be generated and transmitted.
机译:给定的应用程序可以跟踪其执行流程。与执行流中标识的输入相关联的约束和/或变换被反映在一组候选测试有效载荷上。基于检测的应用程序的执行流基于输入满足约束的输入达到约束而安全操作的执行流程来修改或修剪候选测试有效载荷,而有效载荷可能不满足。如果候选测试有效载荷的集合在到达安全操作时不为空,则确定给定应用程序具有漏洞,并且可以生成并发送发出警告的信号。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号