A method for discovering security bugs of software based on AOE Network

Jiadong Ren*, Changzhen Hu, Kunsheng Wang, Ruiqing Ma

*此作品的通讯作者

科研成果: 期刊稿件文章同行评审

4 引用 (Scopus)

摘要

The existing methods for discovering security bugs all focus on one or twocategories of security properties each. Moreover, the false positive rates ofthe existing methods are all high. In this paper, we present a new approach forfinding hugs based on AOE networks. This method models the security propertiesusing FSA and the security hugs to he verified as AOE networks. First, themethod identifies whether the security-relevant operations violate securityproperties. Then, the method continues to check if those security-relevantoperations violating security properties obey bug properties described by AOEnetworks, and the security-relevant operations obeying bug properties are viewedas the real bug operations. Experimental analysis shows that our method has alower false positive rate and can check several security properties at once.ICIC International

源语言英语
页(从-至)1081-1086
页数6
期刊ICIC Express Letters
3
4
出版状态已出版 - 12月 2009

指纹

探究 'A method for discovering security bugs of software based on AOE Network' 的科研主题。它们共同构成独一无二的指纹。

引用此