摘要
以信息安全理论和软件逆向工程技术为依托,研究了操作系统安全机制复合行为模型掘取技术及其实现方法和技术路线。通过结合操作系统的多尺度软件逆向理解技术,对操作系统安全机制的相关程序进行逆向分析、模型掘取和形式化描述,从而发现潜在漏洞、后门、隐通道等操作系统高层安全机制存在的安全问题,为实施修补、反制及利用等相应安全措施提供有力依据。在该技术基础上实现了一套原型系统,实验验证该系统的程序理解和模型掘取结果满足要求。
Based on theories of information security and technology of software reverse engineering, studied the technology and realizable method of complex behavior model mining for operating system security mechanism. By using the technologies of multi-scale program comprehension, reverse analysis, model mining and formal description to the programs correlative with operating system security mechanism, found security problems of security mechanism, such as leaks, back doors, covert channels and so on, in order to provide the conclusive evidences for security defence measures. A prototype was implemented and used to verify the security of operating system. The result of program comprehension and model mining satisfies requirements.
出处
《计算机应用研究》
CSCD
北大核心
2009年第1期314-316,共3页
Application Research of Computers
基金
国家"863"计划资助项目(2006AA01Z406)
关键词
操作系统安全机制
静态分析
程序理解
模型掘取
形式化描述
operating system security mechanism
static analysis
program comprehension
model mining
formal description