期刊文献+

软件安全漏洞挖掘技术的研究 被引量:4

The Research on Software Security Vulnerabilities Mining
下载PDF
导出
摘要 本文首先通过对软件安全漏洞发掘相关技术的研究和分析,针对静态分析和动态分析的优缺点,提出一套比较实用的软件安全漏洞挖掘技术,然后使用该技术对自编的overflow-strepy.exe和no-loop-overflow-strepy.exe两个实际应用程序进行检测,准确的检测出了程序中的漏洞。 At first, according to the research and analysis to the technology about the software security vulnerabilities, and dealing with the strengths and weaknesses of the static and dynamic analysis, this paper proposed a more practical mining of software security vulnerabilities, and then use the selfedited technology to detect two practical applications, which are the overflow-strepy.exe and no-loopoverflow-strepy.exe, and it detected the loopholes accurately.
出处 《山东纺织经济》 2010年第5期107-109,共3页 Shandong Textile Economy
关键词 软件安全 静态分析 动态检测 漏洞挖掘 software safety, static analysis, dynamic detection, loophole mining
  • 相关文献

参考文献4

二级参考文献60

  • 1王前,余静,陈性元,谢寿生.安全隐患检测系统的设计与实现[J].微计算机信息,2005,21(10X):3-4. 被引量:5
  • 2M. Rekoff. On reverse engineering [J].IEEE Transactions on Systems, Man and Cybernetics, 1955; 15(2):244-252
  • 3Greg Hoglund.软件剖析-代码攻防之道[M].北京:清华大学出版社,2005
  • 4Halvar Flake. Structural Comparison of Executable Objects[J].DIMVA 2004:161-173
  • 5Bisbey,R.and D.Hollingsworth,Protection Analysis Project Final Report,Information Sciences Institute,University of Southern California,Marina Del Rey,CA,1978.
  • 6Ram Chillarege ODC for Process Measurement.Analysis and Control.Proc.of the Fourth International Conference on Software Quality,ASQC Software Division,Oct.3~5,1994 McLean,VA.
  • 7T.Aslam,I.Krsul,E.Spafford,Use of a Taxonomy of Security Faults,Proc.19th NIST-NCSC National Information Systems Security Conference.1996.
  • 8Eugene H.Spafford,Common System Vulnerabilities.Proceedings of the Workshop on Future Directions in Computer Misuse and Anomaly Detection pp.34~37,1992.
  • 9R.P.Abbott et al.,Security Analysis and Enhancements of Computer Operating Systems,Report NBSIR 76~1041,Institute for Computer Science and Technology,Natl.Bur.of Stnds,1976.
  • 10Brian Marick,A survey of software fault surveys.Technical Report UIUCDCS-R-90-1651,University of Illinois at Urbana-Champaign,December 1990.

共引文献47

同被引文献15

引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部