首页> 外国专利> SOFTWARE VULNERABILITY ATTACK BEHAVIOR ANALYSIS SYSTEM BASED ON THE SOURCE CODE

SOFTWARE VULNERABILITY ATTACK BEHAVIOR ANALYSIS SYSTEM BASED ON THE SOURCE CODE

机译:基于源代码的软件漏洞攻击行为分析系统

摘要

The present invention relates to a system for analyzing a software vulnerability attack behavior based on a source code, which enables to define a behavior capable of attacking vulnerability of an actual software based on vulnerability detected by a result of information collection, static analysis of a source code, and dynamic analysis of a software, which are used to analyze software vulnerability. The present invention implements a system for analyzing a software vulnerability attach behavior based on a source code, comprising: a vulnerability realizing environment analysis engine for analyzing whether vulnerability is activated or not when a software is actually operated by comparing an environment required for operating the software with an environment in which the vulnerability may be abused; a vulnerability attack flow analysis engine for analyzing whether an attack behavior can be defined as a sequent behavior by being connected to an attack behavior known on a software flow or to another detected vulnerability; and a scenario building engine for building an invasion scenario by determining whether vulnerability which can be realized with respect to a flow in which the vulnerability may be abused and attack techniques based on the results analyzed through each of the vulnerability realizing environment analysis engine and the vulnerability attack flow analysis engine.
机译:本发明涉及一种基于源代码的软件漏洞攻击行为分析系统,其能够基于信息收集,源静态分析结果检测到的漏洞,定义能够攻击实际软件漏洞的行为。代码以及软件的动态分析,用于分析软件漏洞。本发明实现了一种基于源代码分析软件漏洞附着行为的系统,包括:漏洞实现环境分析引擎,用于通过比较软件运行所需的环境来分析当软件实际运行时是否激活了漏洞。具有可能滥用该漏洞的环境;漏洞攻击流分析引擎,用于通过将攻击行为与软件流上已知的攻击行为或与另一检测到的漏洞连接来分析是否可以将攻击行为定义为后续行为;场景构建引擎,其通过基于每个漏洞实现环境分析引擎和该漏洞的分析结果,确定是否可以针对该漏洞被滥用的流程实现可以实现的漏洞以及攻击技术,从而构建入侵场景攻击流分析引擎。

著录项

  • 公开/公告号KR101640479B1

    专利类型

  • 公开/公告日2016-07-18

    原文格式PDF

  • 申请/专利权人 ENKISOFT CO. LTD.;

    申请/专利号KR20150121728

  • 发明设计人 LEE SEUNG HAN;

    申请日2015-08-28

  • 分类号G06F21/57;G06F21/56;

  • 国家 KR

  • 入库时间 2022-08-21 14:12:11

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号