首页> 外国专利> A method and device for code audit

A method and device for code audit

机译:一种代码审核的方法和装置

摘要

The present invention discloses a code audit method, comprising the steps of: tracing a variable in source codes to acquire the processing nodes that process the variable; determining the parent processing nodes of the processing nodes as well as the security attribute of the processing nodes; individually comparing the security attribute of the processing nodes and the security attribute of their parent processing nodes and, in case the security attribute of the parent processing node of a processing node is not a subset of the security attribute of the processing node, determining that there are security vulnerabilities in the processing node. In addition, the present invention further discloses a code audit device. Since the technical solution of the present invention determines whether there are any vulnerabilities in the processing nodes according to their logic for variable processing, it can improve the accuracy of the code audit and truly, accurately reflect any security vulnerabilities in the source codes.
机译:本发明公开了一种代码审计方法,包括以下步骤:在源代码中跟踪变量以获取处理该变量的处理节点;以及确定处理节点的父处理节点以及处理节点的安全属性;分别比较处理节点的安全属性和其父处理节点的安全属性,如果处理节点的父处理节点的安全属性不是处理节点的安全属性的子集,则确定是处理节点中的安全漏洞。另外,本发明还公开了一种代码审核装置。由于本发明的技术方案是根据处理节点的可变逻辑确定处理节点是否存在漏洞,因此可以提高代码审计的准确性,真实,准确地反映源代码中的任何安全漏洞。

著录项

  • 公开/公告号EP2107484A2

    专利类型

  • 公开/公告日2009-10-07

    原文格式PDF

  • 申请/专利权人 SIEMENS AKTIENGESELLSCHAFT;

    申请/专利号EP20090155224

  • 发明设计人 SUI AI FEN;HU JIAN JUN;TANG WEN;

    申请日2009-03-16

  • 分类号G06F21/00;G06F11/36;

  • 国家 EP

  • 入库时间 2022-08-21 19:14:47

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号