Providing a Source Code Security Analysis Model Using Semantic Web Techniques

被引:0
|
作者
EkramiFard, Ala [1 ]
Kahani, Mohsen [1 ]
机构
[1] Ferdowsi Univ Mashhad, Dept Comp Engn, Mashhad, Iran
来源
SECOND INTERNATIONAL CONGRESS ON TECHNOLOGY, COMMUNICATION AND KNOWLEDGE (ICTCK 2015) | 2015年
关键词
Security analysis; source code; semantic web ontology;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Security is one of the main issues in all phases of the software life cycle. Since most software vulnerabilities occur in coding phase, so the secure implementation is very important. Semantic Web ontology expresses the concept of a specific area. According to variety of software systems and manufacturing techniques, the Semantic Web can be effective in production of software systems. Anthology helps to review security holes and bugs in source code and produces appropriate reports. To overcome the problem of variety of source code language, in this paper, an ontology approach for source code security analysis model has been used. In this model, the source code is represented in terms of the RDF triples. The security error patterns are provided in the form of SPARQL queries. The result shows that this approach is promising and can effectively find the security flaw patterns in source codes. Experimental evaluations demonstrate that this approach is feasible and finds bug patterns that implemented. The main advantage of this method is the independence of code analysis and error inference sections so each parts can be developed.
引用
收藏
页码:33 / 37
页数:5
相关论文
共 19 条
  • [1] Predicting Security Vulnerabilities using Source Code Metrics
    Ganesh, Sundarakrishnan
    Ohlsson, Tobias
    Palma, Francis
    PROCEEDINGS OF THE 2021 SWEDISH WORKSHOP ON DATA SCIENCE (SWEDS), 2021,
  • [2] Cross-Language Source Code Re-Use Detection Using Latent Semantic Analysis
    Flores, Enrique
    Barron-Cedeno, Alberto
    Moreno, Lidia
    Rosso, Paolo
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2015, 21 (13) : 1708 - 1725
  • [3] Open Source Web Application Security: A Static Analysis Approach
    Alenezi, Mamdouh
    Javed, Yasir
    2016 INTERNATIONAL CONFERENCE ON ENGINEERING & MIS (ICEMIS), 2016,
  • [4] Application of source code static analysis methods to ensure security of APCS
    Knysh, Alexander, V
    Kobzev, Dmitry A.
    Davidenko, Oksana N.
    Detistov, Sergey A.
    Shechev, Ivan A.
    Khenerina, Alyona A.
    Ulyashev, Ivan I.
    NAUKA I TEHNOLOGII TRUBOPROVODNOGO TRANSPORTA NEFTI I NEFTEPRODUKTOV-SCIENCE & TECHNOLOGIES-OIL AND OIL PRODUCTS PIPELINE TRANSPORTATION, 2021, 11 (03): : 346 - 356
  • [5] Locating Source Code Bugs in Software Information Systems Using Information Retrieval Techniques
    Alawneh, Ali
    Alazzam, Iyad M.
    Shatnawi, Khadijah
    BIG DATA AND COGNITIVE COMPUTING, 2022, 6 (04)
  • [6] A quantitative security evaluation and analysis model for web applications based on OWASP application security verification standard
    Wen, Shao-Fang
    Katt, Basel
    COMPUTERS & SECURITY, 2023, 135
  • [7] Security Analysis for Web Service Behaviors Based on Hierarchical Stochastic Game Model
    Lv Junjie
    Wang Yuanzhuo
    Li Jingyuan
    Meng Kun
    Lin Chuang
    CHINESE JOURNAL OF ELECTRONICS, 2015, 24 (03) : 449 - 454
  • [8] Security Analysis for Web Service Behaviors Based on Hierarchical Stochastic Game Model
    LV Junjie
    WANG Yuanzhuo
    LI Jingyuan
    MENG Kun
    LIN Chuang
    Chinese Journal of Electronics, 2015, 24 (03) : 449 - 454
  • [9] USING CONCEPTS OF TEXT BASED PLAGIARISM DETECTION IN SOURCE CODE PLAGIARISM ANALYSIS
    Duracik, Michal
    Krsak, Emil
    Hrkut, Patrik
    PLAGIARISM ACROSS EUROPE AND BEYOND 2017, 2017, : 177 - 186
  • [10] Formal security analysis of near field communication using model checking
    Alexiou, Nikolaos
    Basagiannis, Stylianos
    Petridou, Sophia
    COMPUTERS & SECURITY, 2016, 60 : 1 - 14