首页> 外国专利> SYSTEM FOR ANALYZING ATTACK ACTION FOR VULNERABLE POINT OF SOURCE CODE-BASED SOFTWARE

SYSTEM FOR ANALYZING ATTACK ACTION FOR VULNERABLE POINT OF SOURCE CODE-BASED SOFTWARE

机译:基于源代码的软件易受攻击点的攻击行为分析系统

摘要

The present invention relates to a system for analyzing an attack action for a vulnerable point of a source code-based software, which can define an action that may actually attack a vulnerable point of software on the basis of a vulnerable point detected as a result of a dynamic analysis of software, a static analysis of a source code, and a collection of information used for analyzing a vulnerable point of software. The system for analyzing an attack action for a vulnerable point of source code-based software is embodied by including: a vulnerable point development environment analysis engine for analyzing whether a vulnerable point is activated when software is actually operated, by comparing an environment required for driving the software and an environment where a vulnerable point may be maliciously used; a vulnerable point attack flow analysis engine for analyzing whether a software flow is expected to lead to a known attack action, or is expected to be connected to another detected vulnerable point and defined as a continuous action; and a scenario establishing engine for establishing a violation scenario by determining an attack technique and whether a developable vulnerable point is included in a flow in which a vulnerable point may be maliciously used, on the basis of each result analyzed through the vulnerable point development environment analysis engine and the vulnerable point attack flow analysis engine.
机译:本发明涉及一种用于分析针对基于源代码的软件的易受攻击点的攻击动作的系统,该系统可基于作为结果的检测到的易受攻击点来定义实际上可攻击软件的易受攻击点的动作。动态分析软件,静态分析源代码以及用于分析软件易受攻击点的信息集合。用于分析基于源代码的软件的易受攻击点的攻击行为的系统包括:易受攻击点开发环境分析引擎,用于通过比较驱动所需的环境来分析在软件实际运行时是否激活了易受攻击的点。可能会恶意使用易受攻击点的软件和环境;脆弱点攻击流程分析引擎,用于分析软件流是预期导致已知的攻击动作,还是预期连接到另一个检测到的脆弱点并定义为连续动作;根据通过脆弱点开发环境分析所分析的每个结果,通过确定攻击技术以及是否可恶意使用脆弱点的流程中是否包含可发展的脆弱点来建立违规情形的场景建立引擎引擎和脆弱点攻击流分析引擎。

著录项

  • 公开/公告号WO2017039136A1

    专利类型

  • 公开/公告日2017-03-09

    原文格式PDF

  • 申请/专利权人 ENKISOFT CO.LTD.;

    申请/专利号WO2016KR07283

  • 发明设计人 LEE SEUNGHAN;

    申请日2016-07-06

  • 分类号G06F21/57;G06F21/56;

  • 国家 WO

  • 入库时间 2022-08-21 13:31:50

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号