Research on the collaborative analysis technology for source code and binary executable based upon the unified defect mode set

被引:0
|
作者
Liang, Xiaobing [1 ]
Cui, Baojiang [2 ]
Lv, Yingjie [1 ]
Fu, Yilun [1 ]
机构
[1] China Elect Power Res Inst, Inst Metrol, Beijing, Peoples R China
[2] Beijing Univ Posts & Telecommun, Sch Comp, Beijing, Peoples R China
来源
2015 9TH INTERNATIONAL CONFERENCE ON INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING IMIS 2015 | 2015年
关键词
Source code defect mode; binary executables defect mode; unified defect mode set; collaborative analysis;
D O I
10.1109/IMIS.2015.40
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The security defect detection technology based on source code usually makes use of static analysis methods to detect security vulnerabilities in the test software, which does not consider the runtime information of program execution and the interaction information with the program runtime surrounding environment, so the security defect detection technology based on source code usually results in higher false positive rate. The binary program vulnerability detection methods based upon dynamic analysis usually have lower false positive rate, but their effectiveness depends entirely on test case generation, the detection efficiency of dynamic analysis based on binary program is lower. Moreover, the research of source code vulnerability detection technique and binary executable vulnerability detection technique are essentially fragmented, without considering the relationship between the two classes of methods. In order to improve the efficiency for source code and binary executables vulnerability detection, we presents a collaborative analysis method for vulnerability detection of source code and binary executables based upon the unified defect mode set, meanwhile, we verify the effectiveness of our method using a concrete example in this paper.
引用
收藏
页码:260 / 264
页数:5
相关论文
empty
未找到相关数据