首页> 外国专利> Rule matching in the presence of languages with no types or as an adjunct to current analyses for security vulnerability analysis

Rule matching in the presence of languages with no types or as an adjunct to current analyses for security vulnerability analysis

机译:在不存在任何类型的语言的情况下进行规则匹配,或者作为当前分析的补充(用于安全漏洞分析)

摘要

A method includes reading by a computing system a rule file including one or more rules having specified paths to methods, each method corresponding to one of a sink, source, or sanitizer. The method includes matching by the computing system the methods to corresponding ones of sinks, sources, or sanitizers determined through a static analysis of an application. The static analysis determines at least flows from sources of information to sinks that use the information. The method includes performing by the computing system, using the sinks, sources, and sanitizers found by the matching, a taint analysis to determine at least tainted flows from sources to sinks, wherein the tainted flows are flows passing information to sinks without the information being endorsed by a sanitizer. Apparatus and program products are also disclosed.
机译:一种方法包括由计算系统读取规则文件,该规则文件包括一个或多个规则,这些规则具有到方法的指定路径,每个方法对应于接收器,源或消毒器中的一个。该方法包括通过计算系统将该方法与通过对应用程序的静态分析确定的接收器,源或消毒剂中的相应的匹配。静态分析至少确定从信息源到使用该信息的接收器的流量。该方法包括由计算系统使用通过匹配找到的汇,源和消毒剂执行的污染分析,以确定至少从源到汇的污染流,其中,污染流是将信息传递到汇而没有信息的流。由消毒剂认可。还公开了设备和程序产品。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号