首页> 外国专利> After-The-Fact Configuration Of Static Analysis Tools Able To Reduce User Burden

After-The-Fact Configuration Of Static Analysis Tools Able To Reduce User Burden

机译:事后配置静态分析工具,可以减少用户负担

摘要

A method includes mapping, based on a first mapping from possible security findings to possible configuration-related sources of imprecision, actual security findings from a static analysis of a program to corresponding configuration-related sources of imprecision, the mapping of the actual security findings creating a second mapping. A user is requested to configure selected ones of the configuration-related sources of imprecision from the second mapping. Responsive to a user updating configuration corresponding to the selected ones of the configuration-related sources of imprecision, security analysis results are updated for the static analysis of the program at least by determining whether one or more security findings from the security analysis results are no longer considered to be vulnerable based on the updated configuration by the user. The updated security analysis results are output. Apparatus and program products are also disclosed.
机译:一种方法包括基于从可能的安全性发现到可能的与配置有关的不精确性源的第一映射,将程序的静态分析中的实际安全性发现从对应的与配置有关的不精确性源进行映射,实际的安全性发现的映射创建第二个映射。要求用户从第二映射配置一些与配置有关的不精确源。响应于用户更新的配置,该配置对应于与配置相关的不精确源中的选定的不精确源,至少通过确定是否已不再从安全性分析结果中得出一个或多个安全性结果来更新安全性分析结果以进行程序的静态分析。根据用户的更新配置,被视为易受攻击。输出更新后的安全性分析结果。还公开了设备和程序产品。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号