首页
学术期刊
论文检测
AIGC检测
热点
更多
数据
Dynamic taint propagation: Finding vulnerabilities without attacking
被引:11
作者
:
Chess, Brian
论文数:
0
引用数:
0
h-index:
0
机构:
Fortify Software, San Mateo, CA
Fortify Software, San Mateo, CA
Chess, Brian
[
1
]
West, Jacob
论文数:
0
引用数:
0
h-index:
0
机构:
Fortify Software, San Mateo, CA
Fortify Software, San Mateo, CA
West, Jacob
[
1
]
机构
:
[1]
Fortify Software, San Mateo, CA
来源
:
Information Security Technical Report
|
2008年
/ 13卷
/ 01期
关键词
:
Quality assurance;
Security;
Software;
Taint propagation;
Vulnerability detection;
D O I
:
10.1016/j.istr.2008.02.003
中图分类号
:
学科分类号
:
摘要
:
We apply dynamic taint propagation to find input validation bugs using less effort than typical security testing. We monitor a target program as it executes in order to track untrusted user input. Our system works in conjunction with normal functional testing, so effort devoted to functional testing can be directly leveraged to uncover vulnerabilities. The result is that we achieve higher test coverage (and therefore find more bugs) than typical security testing techniques and make it practical for quality assurance organizations with no security experience to test the security of the software they examine. © 2008 Elsevier Ltd. All rights reserved.
引用
收藏
页码:33 / 39
页数:6
相关论文
未找到相关数据
未找到相关数据