首页> 外文会议>International Conference on Networks Security, Wireless Communications and Trusted Computing >Qualitative and Quantitative Analysis of Information Leakage in Java Source Code
【24h】

Qualitative and Quantitative Analysis of Information Leakage in Java Source Code

机译:Java源代码中信息泄露的定性和定量分析

获取原文

摘要

Java is a kind of type-safe language, it introduces access control mechanism into bytecode and application layer, so as to guarantee the system resource and running environment avoid the invasion of the malicious code. However, in some information systems, information leakage is not due to the faultiness of the security model, but the absence of the information flow control policy and implementation of that in the source code. So, it is necessary to analyze how information leaks through the source code. This paper surveys information leakage in Java source code by qualitative analysis, and after defining conditional information entropy of the variables, quantitative analysis of information-leak in code is given. Language-based software security researches, new direction in the development of high trusted software, are introduced finally.
机译:Java是一种类型安全的语言,它将访问控制机制引入字节码和应用程​​序层,以保证系统资源和运行环境避免了恶意代码的入侵。然而,在一些信息系统中,信息泄漏不是由于安全模型的故障,而是在源代码中没有信息流控制策略和实现。因此,有必要分析信息如何通过源代码泄露。本文通过定性分析调查Java源代码中的信息泄漏,并在定义变量的条件信息熵之后,给出了代码中信息泄漏的定量分析。基于语言的软件安全研究,最终推出了高可信软件开发的新方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号