首页> 外国专利> Generating sound and minimal security reports based on static analysis of a program

Generating sound and minimal security reports based on static analysis of a program

机译:根据程序的静态分析生成可靠的安全报告和最小限度的报告

摘要

A method is disclosed that includes, using a static analysis, analyzing a software program to determine a number of paths from sources accepting information to sinks using that information or a modified version of that information and to determine multiple paths from the number of paths. The determined multiple paths have a same transition from an application portion of the software program to a library portion of the software program and require a same downgrading action to address a vulnerability associated with source-sink pairs in the multiple paths. The analyzing includes determining the multiple paths using a path-sensitive analysis. The method includes, for the determined multiple paths, grouping the determined multiple paths into a single representative indication of the determined multiple paths. The method includes outputting the single representative indication. Computer program products and apparatus are also disclosed.
机译:公开了一种方法,该方法包括使用静态分析来分析软件程序,以使用该信息或该信息的修改版本来确定从接受信息的源到接收器的路径数量,并从该路径数量确定多个路径。所确定的多个路径具有从软件程序的应用程序部分到软件程序的库部分的相同转换,并且需要相同的降级动作来解决与多个路径中的源-宿对相关联的漏洞。该分析包括使用路径敏感分析来确定多个路径。对于所确定的多个路径,该方法包括将所确定的多个路径分组为所确定的多个路径的单个代表性指示。该方法包括输出单个代表性指示。还公开了计算机程序产品和设备。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号