您的位置: 专家智库 > >

张实睿

作品数:2 被引量:3H指数:1
供职机构:东南大学更多>>
发文基金:国家自然科学基金更多>>
相关领域:自动化与计算机技术更多>>

文献类型

  • 1篇期刊文章
  • 1篇学位论文

领域

  • 2篇自动化与计算...

主题

  • 1篇约束信息
  • 1篇侦测
  • 1篇整数溢出
  • 1篇网络
  • 1篇网络安全
  • 1篇网络安全漏洞
  • 1篇漏洞
  • 1篇安全漏洞
  • 1篇PATH
  • 1篇RELAXA...
  • 1篇SQL注入
  • 1篇DETECT...
  • 1篇METHOD

机构

  • 2篇东南大学
  • 1篇南京大学

作者

  • 2篇张实睿
  • 1篇徐宝文
  • 1篇许蕾

传媒

  • 1篇Journa...

年份

  • 1篇2010
  • 1篇2009
2 条 记 录,以下是 1-2
排序方式:
基于路径松弛的网络安全漏洞侦测
随着互联网的应用与普及,网络安全问题成为人们关注的焦点。在已知的网络安全漏洞中,跨站攻击,SQL注入式攻击以及由整数溢出引发的缓冲区溢出漏洞近年来上升趋势最为明显,造成了很大的危害。相关领域的研究者提出了多种方法加以侦测...
张实睿
关键词:SQL注入整数溢出约束信息
文献传递
Method of integer overflow detection to avoid buffer overflow被引量:3
2009年
A simplified integer overflow detection method based on path relaxation is described for avoiding buffer overflow triggered by integer overflow. When the integer overflow refers to the size of the buffer allocated dynamically, this kind of integer overflow is most likely to trigger buffer overflow. Based on this discovery, through lightly static program analysis, the solution traces the key variables referring to the size of a buffer allocated dynamically and it maintains the upper bound and lower bound of these variables. After the constraint information of these traced variables is inserted into the original program, this method tests the program with test cases through path relaxation, which means that it not only reports the errors revealed by the current runtime value of traced variables contained in the test case, but it also examines the errors possibly occurring under the same execution path with all the possible values of the traced variables. The effectiveness of this method is demonstrated in a case study. Compared with the traditional buffer overflow detection methods, this method reduces the burden of detection and improves efficiency.
张实睿许蕾徐宝文
共1页<1>
聚类工具0