找回密码
 To register

QQ登录

只需一步,快速开始

扫一扫,访问微社区

Titlebook: String Analysis for Software Verification and Security; Tevfik Bultan,Fang Yu,Abdulbaki Aydin Book 2017 Springer International Publishing

[复制链接]
查看: 13664|回复: 49
发表于 2025-3-21 16:13:54 | 显示全部楼层 |阅读模式
书目名称String Analysis for Software Verification and Security
编辑Tevfik Bultan,Fang Yu,Abdulbaki Aydin
视频video
概述This is the first existing book focusing on string analysis.Discusses how string analysis techniques work and how they can be applied to vulnerability detection in modern software applications.This bo
图书封面Titlebook: String Analysis for Software Verification and Security;  Tevfik Bultan,Fang Yu,Abdulbaki Aydin Book 2017 Springer International Publishing
描述.This book discusses automated string-analysis techniques, focusing particularly on automata-based static string analysis. It covers the following topics: automata-bases string analysis, computing pre and post-conditions of basic string operations using automata, symbolic representation of automata, forward and backward string analysis using symbolic automata representation, constraint-based string analysis, string constraint solvers, relational string analysis, vulnerability detection using string analysis, string abstractions, differential string analysis, and automated sanitization synthesis using string analysis...String manipulation is a crucial part of modern software systems; for example, it is used extensively in input validation and sanitization and in dynamic code and query generation. The goal of string-analysis techniques and this book is to determine the set of values that string expressions can take during program execution. String analysis can be used to solve many problems in modern software systems that relate to string manipulation, such as: (1) Identifying security vulnerabilities by checking if a security sensitive function can receive an input string that conta
出版日期Book 2017
关键词Automated sanitization synthesis; Automated string analysis; Computer security; Input validation and sa
版次1
doihttps://doi.org/10.1007/978-3-319-68670-7
isbn_softcover978-3-319-88637-4
isbn_ebook978-3-319-68670-7
copyrightSpringer International Publishing AG 2017
The information of publication is updating

书目名称String Analysis for Software Verification and Security影响因子(影响力)




书目名称String Analysis for Software Verification and Security影响因子(影响力)学科排名




书目名称String Analysis for Software Verification and Security网络公开度




书目名称String Analysis for Software Verification and Security网络公开度学科排名




书目名称String Analysis for Software Verification and Security被引频次




书目名称String Analysis for Software Verification and Security被引频次学科排名




书目名称String Analysis for Software Verification and Security年度引用




书目名称String Analysis for Software Verification and Security年度引用学科排名




书目名称String Analysis for Software Verification and Security读者反馈




书目名称String Analysis for Software Verification and Security读者反馈学科排名




单选投票, 共有 0 人参与投票
 

0票 0%

Perfect with Aesthetics

 

0票 0%

Better Implies Difficulty

 

0票 0%

Good and Satisfactory

 

0票 0%

Adverse Performance

 

0票 0%

Disdainful Garbage

您所在的用户组没有投票权限
发表于 2025-3-21 22:55:24 | 显示全部楼层
发表于 2025-3-22 00:56:24 | 显示全部楼层
State Space Exploration,ration. We discuss both forward and backward reachability analysis using depth-first search where states of a given string manipulating program are traversed one state at a time. Next, we discuss symbolic reachability analysis, where the basic idea is to perform state exploration using sets of state
发表于 2025-3-22 04:55:23 | 显示全部楼层
发表于 2025-3-22 12:44:40 | 显示全部楼层
Relational String Analysis,ifying properties that depend on relations among string variables. We discuss the basic word equations (over string concatenations) and the corresponding automata constructions. We present a verification technique based on forward symbolic reachability analysis with multi-track automata, conservativ
发表于 2025-3-22 16:47:17 | 显示全部楼层
Abstraction and Approximation,nipulate user input, and their erroneous use is the most common cause of security vulnerabilities in web applications. Unfortunately, verifying string manipulating programs is an undecidable problem in general and any approximate string analysis technique has an inherent tension between efficiency a
发表于 2025-3-22 17:49:06 | 显示全部楼层
Constraint-Based String Analysis,applied to string manipulating programs. However, symbolic execution of string manipulating programs is difficult since solving string constraints is a challenging problem. String constraint solving is challenging due to two main reasons: 1) With the increasing usage of strings in modern software de
发表于 2025-3-22 21:37:34 | 显示全部楼层
发表于 2025-3-23 05:06:13 | 显示全部楼层
Differential String Analysis and Repair,olicies in characterizing good and bad string values. It is often possible, for instance, to encode well-known attacks into security policies (in the form of attack patterns) and write down policies for common input fields such as email address and zip code. In other cases, however, the checks to be
发表于 2025-3-23 06:47:33 | 显示全部楼层
Tools,ed string analysis library called . [.], a vulnerability analysis tool for PHP programs built on . called . [.], an automated repair tool for string manipulating code called . [.], and an automata-based constraint solver for string constraints called . [.].
 关于派博传思  派博传思旗下网站  友情链接
派博传思介绍 公司地理位置 论文服务流程 影响因子官网 SITEMAP 大讲堂 北京大学 Oxford Uni. Harvard Uni.
发展历史沿革 期刊点评 投稿经验总结 SCIENCEGARD IMPACTFACTOR 派博系数 清华大学 Yale Uni. Stanford Uni.
|Archiver|手机版|小黑屋| 派博传思国际 ( 京公网安备110108008328) GMT+8, 2025-5-12 02:44
Copyright © 2001-2015 派博传思   京公网安备110108008328 版权所有 All rights reserved
快速回复 返回顶部 返回列表