SVR-Miner:一种基于大型软件的安全验证规则挖掘和缺陷检测工具

来源 :中国通信 | 被引量 : 0次 | 上传用户:yupeng198652
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
For various reasons, many of the security programming rules applicable to specific software have not been recorded in official documents, and hence can hardly be employed by static analysis tools for detection. In this paper, we propose a new approach, named SVR-Miner (Security Validation Rules Miner), which uses frequent sequence mining technique [1-4] to automatically infer implicit secu-rity validation rules from large software code written in C programming language. Different from the past works in this area, SVR-Miner introduces three techniques which are sensitive thread, program sli-cing [5-7], and equivalent statements computing to improve the accuracy of rules. Experiments with the Linux Kernel demonstrate the effectiveness of our approach. With the ten given sensitive threads, SVR-Miner automatically generated 17 security vali-dation rules and detected 8 violations, 5 of which were published by Linux Kernel Organization before we detected them. We have reported the other three to the Linux Kernel Organization recently.
其他文献
当前计价体系框架下,工程项目能否以合理的价格中标,已成为投标单位关注的重点本文从合理最低评标价法的概念以及实际应用入手,讨论如何保障合理最低评标价法的应用,期与同行共商
目的 探讨基础护理服务对脑血管病患者焦虑水平的影响.方法 将200例脑血管病患者分为对照组和实验组,每组100例,对照组行常规护理,实验组除常规护理外,还由责任护士实施基础
联系实际的应用题,反映了现实世界一些元素或量之间的数量关系.通过解答应用题可以开发智力、培养学生分析问题和解决问题的能力,因此,应用题是中学数学的重要内容.而列方程解应用
从前,有一只自以为很能干的小蜜蜂。它总觉得自己做的事比其他同伴多,但吃的蜂蜜却很少。所以它一气之下,一封信也没留,离开了蜂群。飞呀飞,飞呀飞,小蜜蜂来到了一个美丽的地
星期六那天,春光明媚,我和外公、外婆一起去乡下玩。好久没吃到野菜了,于是,外婆和外公决定带我一起去菜地里挖野菜。来到菜地里,我看到菜地早已经脱去它厚厚的冬衣,换上了新
随着我国经济的快速发展,现代化城市建设的步伐异常迅猛,城市建设在合理布局的基础上不仅要符合时代发展趋势,也要以人为本突出美学特色.本文就城市建设中的美学运用进行了多
Abstract:Based on microscope and image processing,a new method of auto tool setting for micro milling was presented.Firstly,a realtime image of tool setting are
Modified constant modulus and recursive least squares (MCMA-RLS) algorithm is proposed to cancel interference caused by the variable frequency offset (FO) in th
Packet classification is crucial to the implementation of advanced network services that require the capability to distinguish traffic in different flows,such a
The seismic safety of the reinforcement dam slope is studied through shaking table test and numerical simulation.The dynamic characteristics of dam slopes,failu