节点文献

基于静态信息流跟踪的输入验证漏洞检测方法

Static information flow tracking based approach to detect input validation vulnerabilities

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 万志远周波

【Author】 WAN Zhi-yuan;ZHOU Bo;College of Computer Science and Technology,Zhejiang University;

【机构】 浙江大学计算机科学与技术学院

【摘要】 针对基于静态分析的漏洞检测技术的高误报率问题,提出基于静态信息流跟踪技术的输入验证漏洞检测方法.在静态代码分析工具FindBugs上实现了该方法,对该方法的漏洞检测精确度和性能进行评估.实验结果表明,采用该方法能够有效地检测输入验证漏洞,在不明显降低运行性能的前提下,将FindBugs的输入验证漏洞检测误报率降低了55.7%.

【Abstract】 An approach based on static information flow tracking was proposed to detect input validation vulnerabilities in order to reduce the false positive rate of vulnerability detection techniques based on static analysis.The approach was implemented on top of the static code analysis tool FindBugs.The performance and precision of our approach were evaluated.Experimental results show that our approach can effectively detect input validation vulnerabilities.The false positive rate of FindBugs was reduced by 55.7% without significantly slowing the performance.

  • 【文献出处】 浙江大学学报(工学版) ,Journal of Zhejiang University(Engineering Science) , 编辑部邮箱 ,2015年04期
  • 【分类号】TP393.08
  • 【被引频次】11
  • 【下载频次】222
节点文献中: 

本文链接的文献网络图示:

本文的引文网络