Invention Grant
US09230099B1 Systems and methods for combining static and dynamic code analysis
有权
用于组合静态和动态代码分析的系统和方法
- Patent Title: Systems and methods for combining static and dynamic code analysis
- Patent Title (中): 用于组合静态和动态代码分析的系统和方法
-
Application No.: US14231663Application Date: 2014-03-31
-
Publication No.: US09230099B1Publication Date: 2016-01-05
- Inventor: Bruce McCorkendale , Sheng Gong , Wei Guo Eric Hu , Ge Hua Huang , Jun Mao , Qingchun Meng , Xue Feng Tian , Xiaole Zhu
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: ALG Intellectual Property, LLC
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F21/52 ; G06F21/60 ; G06F11/00 ; G06F12/16 ; G08B23/00 ; G06F11/30

Abstract:
A computer-implemented method for combining static and dynamic code analysis may include 1) identifying executable code that is to be analyzed to determine whether the executable code is capable of leaking sensitive data, 2) performing a static analysis of the executable code to identify one or more objects which the executable code may use to transfer sensitive data, the static analysis being performed by analyzing the executable code without executing the executable code, 3) using a result of the static analysis to tune a dynamic analysis to track the one or more objects identified during the static analysis, and 4) performing the dynamic analysis by, while the executable code is being executed, tracking the one or more objects identified during the static analysis to determine whether the executable code leaks sensitive data via the one or more objects. Various other methods, systems, and computer-readable media are also disclosed.
Information query