Previous Articles    

A Method of Analyzing and Localizing Software Vulnerability Automatically

 WANG  Tong-Lei, CHEN  Chao-Hui-   

  1. Beijing Institute of Control Engineering, Beijing 100190, China.
  • Online:2018-04-25 Published:2018-05-16

Abstract: Abstract:In order to meet the requirements of high reliability that is required by many embedded software in aerospace field, a method is designed to analyze and localize the software vulnerability automatically. Based on program slicing technique and improved forward computation algorithm of dynamic slicing, firstly this method collects the program dynamic information at runtime via using dynamic slicing; and then it constructs the program slice spectrum and calculates the likelihood of each slicing statement being vulnerable by some statistics; and last it reports the localization result of software vulnerability. After discovering the vulnerability in the software, this method can analyze and localize the root that causes this vulnerability. We develop a tool to test this method and the experiment proves its effectiveness.  

Key words: Keywords:software vulnerability, program slice, program spectrum, vulnerability localization

CLC Number: 

  •