发明授权
- 专利标题: Software analysis framework
- 专利标题(中): 软件分析框架
-
申请号: US11415442申请日: 2006-05-01
-
公开(公告)号: US07752609B2公开(公告)日: 2010-07-06
- 发明人: Christien R. Rioux
- 申请人: Christien R. Rioux
- 申请人地址: US MA Burlington
- 专利权人: Veracode, Inc.
- 当前专利权人: Veracode, Inc.
- 当前专利权人地址: US MA Burlington
- 代理机构: Goodwin Procter LLP
- 主分类号: G06F9/45
- IPC分类号: G06F9/45 ; G06F9/445
摘要:
Presently described is a decompilation method of operation and system for parsing executable code, identifying and recursively modeling data flows, identifying and recursively modeling control flow, and iteratively refining these models to provide a complete model at the nanocode level. The nanocode decompiler may be used to determine if flaws, security vulnerabilities, or general quality issues exist in the code. The nanocode decompiler outputs in a standardized, human-readable intermediate representation (IR) designed for automated or scripted analysis and reporting. Reports may take the form of a computer annotated and/or partially human annotated nanocode listing in the above-described IR. Annotations may include plain English statements regarding flaws and pointers to badly constructed data structures, unchecked buffers, malicious embedded code or “trap doors,” and the like. Annotations may be generated through a scripted analysis process or by means of an expert-enhanced, quasi-autonomous system.
公开/授权文献
- US20060253841A1 Software analysis framework 公开/授权日:2006-11-09
信息查询