首页 / 资料库 / 文献详情

一种基于一阶逻辑的软件代码安全性缺陷静态检测技术

XiaoJun QINShuitao GanZuoning Chen

2014Scientia Sinica InformationisComputer Science被引 2开放获取

出版方页面 →

摘要

The secure vulnerability of software codes is an important vulnerability which may cause a disaster in the software system. The automatic detecting and locating technologies for this type of vulnerability have a significant meaning in the software preserving and evolution. This paper proposes and implements a formal detection method which is a static detecting method of software code secure vulnerability based on first-order logic. Our method defines the formula of pattern path by combining propositional logic and predicate logic. Some expressions of proposition logical construction function related to dependence relation is used as directed conditions for creating the nodes of pattern path. Then we formulate various types of software code secure vulnerabilities and turn the efforts in finding vulnerability to judging the existence of pattern path in limited state space among corresponding intermediate codes. The experiment results show that our method is fit for detecting most types of software code secure vulnerability. It punctually finds out ten known and two 0-day vulnerabilities in 13 open source projects including openssl, wu-ftpd, etc. Comparing to existing static analysis methods, such as module checking, the test time in suing this model is almost in line with the size of the code.

引用本文(GB/T 7714)

XiaoJun QIN, Shuitao Gan, Zuoning Chen. 一种基于一阶逻辑的软件代码安全性缺陷静态检测技术[J]. Scientia Sinica Informationis, 2014.

引文网络

参考文献与被引分析加载中…

DOI:https://doi.org/10.1360/n112013-00095

本站仅收录题录与摘要供学习参考,全文版权归属出版方;如有侵权请联系我们删除。