首页> 外国专利> BUFFER OVERFLOW VULNERABILITY DETECTION PROGRAM AND BUFFER OVERFLOW VULNERABILITY DETECTION METHOD

BUFFER OVERFLOW VULNERABILITY DETECTION PROGRAM AND BUFFER OVERFLOW VULNERABILITY DETECTION METHOD

机译:缓冲区溢流脆弱性检测程序及缓冲区溢流脆弱性检测方法

摘要

PROBLEM TO BE SOLVED: To detect buffer overflow vulnerability while placing no burden on a programmer, preventing detection failures, and reducing detection errors.;SOLUTION: An area-access formula including an area formula representing an area secured and an index formula designating an access position in the area represented by the area formula is detected from a program to be analyzed. The size formula of the area represented by the area formula is detected. A buffer overflow condition in which, upon the execution of instructions included in the area-access formula, a buffer overflow occurs leading to access outside of the area represented by the area formula is calculated using the index formula and the size formula. An execution path from an instruction disposed upstream of a source program to an instruction including the area-access formula is specified. Based on a substitution instruction disposed on the execution path, the buffer overflow condition is traced back toward the upstream side of the execution path to find the expression of the buffer overflow condition on the upstream side.;COPYRIGHT: (C)2006,JPO&NCIPI
机译:解决的问题:在不给程序员带来负担的情况下检测缓冲区溢出漏洞,防止检测失败,并减少检测错误。解决方案:区域访问公式,包括代表安全区域的区域公式和指定访问的索引公式从要分析的程序中检测由面积公式表示的面积中的位置。检测由面积公式表示的面积的尺寸公式。使用索引公式和大小公式来计算缓冲区溢出条件,在该缓冲区溢出条件中,一旦执行了区域访问公式中包含的指令,就会发生缓冲区溢出,从而导致访问区域公式所表示的区域之外。指定了从放置在源程序上游的指令到包括区域访问公式的指令的执行路径。根据执行路径上放置的替换指令,将缓冲区溢出条件追溯到执行路径的上游,以查找上游侧缓冲区溢出条件的表达式。版权所有:(C)2006,JPO&NCIPI

著录项

  • 公开/公告号JP2006031363A

    专利类型

  • 公开/公告日2006-02-02

    原文格式PDF

  • 申请/专利权人 MITSUBISHI RESEARCH INSTITUTE INC;

    申请/专利号JP20040208709

  • 发明设计人 NAKAMURA TAKEKAZU;

    申请日2004-07-15

  • 分类号G06F21/22;

  • 国家 JP

  • 入库时间 2022-08-21 21:52:59

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号