一种基于补丁比对和静态污点分析的漏洞定位技术研究  被引量:3

Research on a Vulnerability Location Technology Based on Patch Matching and Static Taint Analysis

在线阅读下载全文

作  者:达小文 毛俐旻 吴明杰 郭敏 

机构地区:[1]北京计算机技术及应用研究所,北京100854

出  处:《信息网络安全》2017年第9期5-9,共5页Netinfo Security

摘  要:目前对于开源软件的漏洞定位分析较为缺乏,且缺少一种自动化的快速定位方法。针对这些不足,文章提出一种基于补丁比对和静态污点分析的漏洞定位方法。该方法通过分析大量开源软件的缓冲区溢出错误的实例,提取6种缓冲区错误的漏洞定位模型;通过将补丁比对和污点传播结合,生成污点传播路径图;将补丁源码的污点传播路径图与定位模型匹配以定位某小块代码,采用污点查找精确定位漏洞所在行。At present,there is a lack of the analysis for vulnerabilities location m open source software and a lack of an automatic method for fast locating the vulnerabilities. To address these issues, this paper proposes a vulnerabilities location method based on patch matching and the static tamts analysis. By analyzing a large number of buffer errors instances of open source software,six wlnerabilities location models of buffer errors are extracted. By combining patch matching with taint propagation, a taint propagation path graph is generated. Match the taint propagation graph of patched source with the location models to locate a small block of code,which then locates vulnerabilities code rows accurately by searching for taints.

关 键 词:漏洞定位 补丁比对 污点分析 缓冲区错误 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象