首页> 外国专利> Static tainting analysis system and method for taint analysis of computer program code-lysis

Static tainting analysis system and method for taint analysis of computer program code-lysis

机译:静态污点分析系统及计算机程序代码解析的污点分析方法

摘要

A method is provided to infer taintedness in code expressions encoded in a computer readable device comprising: configuring a computer system to, store a representation of a computer program that is to be evaluated in non-transitory storage media; identify within the representation a pointer cast operation; determine whether an identified cast operation involves a cast from a pointer to a raw memory data type to a pointer to a structured data type; determine whether a structured data type casted to is associated with indicia of externalness; designating data addressed by that pointer as tainted; and determine whether data designated as tainted is consumed by an operation in the computer program that acts as a taintedness sink.
机译:提供了一种用于推断在计算机可读设备中编码的代码表达式中的污点的方法,该方法包括:将计算机系统配置为将要评估的计算机程序的表示存储在非暂时性存储介质中;在表示中标识指针转换操作;确定所标识的转换操作是否涉及从指针到原始存储器数据类型的转换到指针到结构化数据类型的转换;确定强制转换为结构化数据类型是否与外部性标记相关;将该指针指向的数据指定为已污染;确定被污染的数据是否被用作污染沉的计算机程序中的操作所消耗。

著录项

  • 公开/公告号EP2696288A1

    专利类型

  • 公开/公告日2014-02-12

    原文格式PDF

  • 申请/专利权人 COVERITY INC.;

    申请/专利号EP20130179799

  • 发明设计人 SCOTT ROGER H.;CHOU ANDY C.;

    申请日2013-08-08

  • 分类号G06F11/36;

  • 国家 EP

  • 入库时间 2022-08-21 15:46:49

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号