Invention Grant
- Patent Title: Answering security queries statically based on dynamically-determined information
- Patent Title (中): 基于动态确定的信息静态地回答安全查询
-
Application No.: US12957529Application Date: 2010-12-01
-
Publication No.: US08646087B2Publication Date: 2014-02-04
- Inventor: Marco Pistola , Omer Tripp , Peter K. Malkin
- Applicant: Marco Pistola , Omer Tripp , Peter K. Malkin
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Harrington & Smith
- Agent Louis J. Percello
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F21/00

Abstract:
A method includes analyzing execution of a software program, the software program having sources returning values, sinks that perform security-sensitive operations on those returned values or modified versions of the returned values, and flows of the returned values to the sinks, the analyzing determining a first set of methods having access to a value returned from a selected one of the sources. A static analysis is performed on the software program, the static analysis using the first set of methods to determine a second set of methods having calling relationships with the selected source, the static analysis determining whether the returned value from the selected source can flow through a flow to a sink that performs a security-sensitive operation without the flow to the sink being endorsed, and in response, indicating a security violation. Apparatus and computer program products are also disclosed.
Public/Granted literature
- US20120144491A1 Answering Security Queries Statically Based On Dynamically-Determined Information Public/Granted day:2012-06-07
Information query