期刊文献+

基于动态符号执行技术的代码安全检测模型研究

Research on Code Security Detection Model Based on Dynamic Symbol Execution Technology
下载PDF
导出
摘要 为了更高效地进行代码安全检测,文章基于动态符号执行技术,针对其存在的执行路径空间爆炸、高效约束求解开销以及程序设计语言兼容性这3个不足进行优化,并在此基础上提出了一种基于优化搜索策略动态符号执行的代码安全检测模型。该模型结合了当前主流的代码安全检测技术,提出了一种新型的安全缺陷分类方法,并优化了路径搜索策略,从而可以更加准确、高效地检测出代码中存在的安全问题。 In order to carry out code security detection more efficiently,based on dynamic symbol execution technology,this paper optimizes its three limitations of execution path space explosion,efficient constraint solution overhead,and programming language compatibility,and proposes a code security detection model based on dynamic symbol execution of optimized search strategy.This model combines the current mainstream code security detection technology,using a new classification method of security defects,and the path search strategy is optimized to detect the security problems in the code more accurately and efficiently.
作者 陈莉娟 喻金龙 CHEN Lijuan;YU Jinlong(Hubei Huazhong Electric Power Technology Development Co.,Ltd.,Wuhan 430077,China)
出处 《电力信息与通信技术》 2019年第1期127-132,共6页 Electric Power Information and Communication Technology
关键词 动态符号执行 代码安全缺陷分类 路径搜索 路径约束求解 代码安全检测 dynamic symbol execution code security defect classification path search path constraint solving code security detection
  • 相关文献

参考文献9

二级参考文献31

  • 1罗文杰,高阳,王皓,李凡长.CALO研究进展分析[J].计算机研究与发展,2006,43(z1):12-17. 被引量:1
  • 2季晓慧,张健.求解布尔与非线性数值约束相混合的约束问题(英文)[J].软件学报,2005,16(5):659-668. 被引量:4
  • 3季晓慧,张健.一种求解混合约束问题的快速完备算法[J].计算机研究与发展,2006,43(3):551-556. 被引量:2
  • 4Zhang Jian,Xu Chen,Wang Xiao-liang.Path-oriented test data generation using symbolic execution and constraint solving techniques[C]//Proceedings of the Second International Conference on Software Engineering and Formal Methods(SEFM'04),2004.
  • 5Cadar C,Ganesh V,Pawlowski P M,et al.EXE:Automatically generating inputs of death[C]//CCS'06,Alexandria,Virginia,USA,October 30-November 3,2006.
  • 6Dolby J,Vasiri M,Tip F.Finding bugs efficiently with a SAT solver[C]//ESEC/FSE ' 07,Cavtatnear Dubrovnik,Croatia,September 3-7,2007.
  • 7Ganov S R,Killmar C,Khnrshid S,et al.Test generation for graphical user interfaces based on symbolic execution[C]//AST'08,Leipzig,Germany,May 11,2008.
  • 8Chess B,West J.安全编程-代码静态分析[M].董启雄,译.北京:机械工业出版社,2008:12-28.
  • 9Godefroid P, Klarlund N, Sen K. DART: directed automated ran- dom testing [ J]. ACM Sigplan Notices ,2005,40(6) :213-223.
  • 10Sen K, Marinov D, Agha G. CUTE:a concolic unit testing engine for C [ C]. Proceedings of the 10th European Software Engineering Conference Held Jointly with 13th ACM SIGSOFT International Symposium on Foundations of Software Engineering, New York, USA,2005 : 263 -272.

共引文献38

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部