首页> 外国专利> Determining the vulnerability of computer software applications to privilege-escalation attacks

Determining the vulnerability of computer software applications to privilege-escalation attacks

机译:确定计算机软件应用程序对特权升级攻击的脆弱性

摘要

Determining the vulnerability of computer software applications to privilege-escalation attacks, such as where an instruction classifier is configured to be used for identifying a candidate access-restricted area of the instructions of a computer software application, and a static analyzer is configured to statically analyze the candidate access-restricted area to determine if there is a conditional instruction that controls execution flow into the candidate access-restricted area, perform static analysis to determine if the conditional instruction is dependent on a data source within the computer software application, and designate the candidate access-restricted area as vulnerable to privilege-escalation attacks absent either of the conditional instruction and the date source.
机译:确定计算机软件应用程序对特权升级攻击的脆弱性,例如将指令分类器配置为用于识别计算机软件应用程序的指令的候选访问受限区域,而将静态分析器配置为静态分析候选访问限制区域,以确定是否存在控制执行流进入候选访问限制区域的条件指令,执行静态分析,以确定条件指令是否依赖于计算机软件应用程序中的数据源,并指定由于没有条件指令和日期源,因此容易受到特权升级攻击的候选访问限制区域。

著录项

  • 公开/公告号US8914890B2

    专利类型

  • 公开/公告日2014-12-16

    原文格式PDF

  • 申请/专利权人 MARCO PISTOIA;ORI SEGAL;OMER TRIPP;

    申请/专利号US201113018342

  • 发明设计人 ORI SEGAL;OMER TRIPP;MARCO PISTOIA;

    申请日2011-01-31

  • 分类号G06F11/00;H04L29/06;G06F21/57;G06F21/56;

  • 国家 US

  • 入库时间 2022-08-21 15:18:15

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号