作者
Wes Masri, Andy Podgurski
发表日期
2008/10/1
期刊
Computers & Security
卷号
27
期号
5-6
页码范围
176-187
出版商
Elsevier Advanced Technology
简介
This paper presents a new approach to detecting software security failures, whose primary goal is facilitating identification and repair of security vulnerabilities rather than permitting online response to attacks. The approach is based on online capture of executions and offline execution replay, profiling, and analysis. It employs fine-grained dynamic information flow analysis in conjunction with anomaly detection. This approach, which we call information flow anomaly detection, is capable of detecting a variety of security failures, including both ones that involve violations of confidentiality or integrity requirements and ones that do not. A prototype tool called DynFlow implementing the approach has been developed for use with Java byte code programs. To illustrate the potential of the approach, it is applied to detect security failures of four open source systems. Also, its effectiveness is compared to the effectiveness of …
引用总数
200820092010201120122013201420152016201720182019202020212022202311234313332114