首页> 外国专利> APPARATUS AND METHOD FOR DETECTING WEAKNESS OF SOURCE CODE SECURITY IN REAL TIME ACCORDING TO FILE CHANGE

APPARATUS AND METHOD FOR DETECTING WEAKNESS OF SOURCE CODE SECURITY IN REAL TIME ACCORDING TO FILE CHANGE

机译:根据文件更改实时检测源代码安全性弱点的装置和方法

摘要

Disclosed are an apparatus and a method for detecting security weakness of a source code in real time according to a file change. In the apparatus and the method for detecting security weakness of a source code in real time according to a file change according to an embodiment of the present invention, when a developer generates a file, a hash value of the file is generated. At least one method from a source code constituting the file and the other method called by the execution of the at least one method are extracted. The hash value, the at least one method and the other method are stored in a database. When a storage event for the file occurs due to the correction of the file by the developer, security weakness detection is not performed on the whole source code constituting the file. Instead, whether the file is changed is firstly checked through comparison of hash values for the file, and then when the file is checked to be changed, referring to the database, whether the at least one method constituting the file is changed is checked, and then security weakness detection is performed only on the other method called by the changed method and according to execution of the applicable method, thereby shortening the time required for security weakness detection to be performed as the file is changed to allow the security weakness detection to be performed on the source code of the applicable file in real time according to the file change.;COPYRIGHT KIPO 2016
机译:公开了一种根据文件改变实时检测源代码的安全弱点的装置和方法。在根据本发明实施例的用于根据文件变化实时检测源代码的安全性弱点的装置和方法中,当开发人员生成文件时,生成文件的哈希值。从构成文件的源代码中提取至少一种方法,并通过执行至少一种方法来调用另一种方法。哈希值,至少一种方法和另一种方法被存储在数据库中。当由于开发人员对文件的纠正而发生文件的存储事件时,不会对构成文件的整个源代码执行安全漏洞检测。相反,首先通过比较文件的哈希值来检查文件是否被改变,然后当检查文件以被改变时,参考数据库,检查构成文件的至少一种方法是否被改变,以及然后仅对更改方法调用的其他方法并根据适用方法的执行情况执行安全漏洞检测,从而缩短了文件更改时执行安全漏洞检测所需的时间,从而可以进行安全漏洞检测根据文件更改实时对适用文件的源代码执行。; COPYRIGHT KIPO 2016

著录项

  • 公开/公告号KR101563494B1

    专利类型

  • 公开/公告日2015-10-27

    原文格式PDF

  • 申请/专利权人 SOFTFORUM CO. LTD.;

    申请/专利号KR20150075038

  • 发明设计人 JEONG JONG MINKR;

    申请日2015-05-28

  • 分类号G06F21/56;G06F21/50;

  • 国家 KR

  • 入库时间 2022-08-21 14:57:31

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号