- 专利标题: DETERMINING THE VULNERABILITY OF COMPUTER SOFTWARE APPLICATIONS TO PRIVILEGE-ESCALATION ATTACKS
-
申请号: US13542214申请日: 2012-07-05
-
公开(公告)号: US20120272322A1公开(公告)日: 2012-10-25
- 发明人: Marco PISTOIA , Ori SEGAL , Omer TRIPP
- 申请人: Marco PISTOIA , Ori SEGAL , Omer TRIPP
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 主分类号: G06F11/30
- IPC分类号: G06F11/30 ; G06F21/00
摘要:
Determining the vulnerability of computer software applications to privilege-escalation attacks, such as where an instruction classifier is configured to be used for identifying a candidate access-restricted area of the instructions of a computer software application, and a static analyzer is configured to statically analyze the candidate access-restricted area to determine if there is a conditional instruction that controls execution flow into the candidate access-restricted area, perform static analysis to determine if the conditional instruction is dependent on a data source within the computer software application, and designate the candidate access-restricted area as vulnerable to privilege-escalation attacks absent either of the conditional instruction and the date source.
公开/授权文献
信息查询