کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
472538 698727 2012 12 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Static program analysis assisted dynamic taint tracking for software vulnerability discovery
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر علوم کامپیوتر (عمومی)
پیش نمایش صفحه اول مقاله
Static program analysis assisted dynamic taint tracking for software vulnerability discovery
چکیده انگلیسی

The evolution of computer science has exposed us to the growing gravity of security problems and threats. Dynamic taint analysis is a prevalent approach to protect a program from malicious behaviors, but fails to provide any information about the code which is not executed. This paper describes a novel approach to overcome the limitation of traditional dynamic taint analysis by integrating static analysis into the system and presents framework SDCF to detect software vulnerabilities with high code coverage. Our experiments show that SDCF is not only able to provide efficient runtime protection by introducing an overhead of 4.16× based on the taint tracing technique, but is also capable of discovering latent software vulnerabilities which have not been exploited, and achieve code coverage of more than 90%.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computers & Mathematics with Applications - Volume 63, Issue 2, January 2012, Pages 469–480
نویسندگان
, , , ,