首页> 外国专利> Entropy-based detection of sensitive information in code

Entropy-based detection of sensitive information in code

机译:基于熵的代码中敏感信息检测

摘要

Techniques are described for identifying security credentials or other sensitive information based on an entropy-based analysis of information included in documents such as source code files, object code files, or other types of files. A baseline information entropy may be determined for one or more documents, indicating a baseline level of randomness for information in the document(s). One or more of the documents may be analyzed to identify the presence of high entropy portions that have an information entropy above a threshold value. The threshold value may be based on the baseline information entropy, or based on other criteria such as a programming language of the document(s). Because security credentials may have a higher level of information entropy than the surrounding code, any high entropy portions of the document(s) may be identified as potential security risks.
机译:描述了用于基于对包括在诸如源代码文件,目标代码文件或其他类型的文件的文档中的信息的基于熵的分析来识别安全证书或其他敏感信息的技术。可以为一个或多个文档确定基线信息熵,该基线信息熵指示文档中信息的基线随机性水平。可以分析一个或多个文档以识别信息熵高于阈值的高熵部分的存在。阈值可以基于基线信息熵,或者基于其他标准,例如文档的编程语言。因为安全凭证可能具有比周围代码更高的信息熵级别,所以可以将文档的任何高熵部分标识为潜在的安全风险。

著录项

  • 公开/公告号US9336381B1

    专利类型

  • 公开/公告日2016-05-10

    原文格式PDF

  • 申请/专利权人 AMAZON TECHNOLOGIES INC.;

    申请/专利号US201313858448

  • 发明设计人 THIBAULT CANDEBAT;DAVID JAMES KANE-PARRY;

    申请日2013-04-08

  • 分类号G06F21/00;G06F21/50;

  • 国家 US

  • 入库时间 2022-08-21 14:28:16

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号