GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Fachbereiche
  • Softwaretechnik (SWT)
  • Softwaretechnik-Trends
  • Softwaretechnik-Trends 37(3) - 2017
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Fachbereiche
  • Softwaretechnik (SWT)
  • Softwaretechnik-Trends
  • Softwaretechnik-Trends 37(3) - 2017
  • Dokumentanzeige

Vulnerability Recognition by Execution Trace Differentiation

Autor(en):
Viertel, Fabien Patrick [DBLP] ;
Karras, Oliver [DBLP] ;
Schneider, Kurt [DBLP]
Zusammenfassung
In context of security, one of the major problems for software development is the difficult and timeconsuming task to find and fix known vulnerabilities through the vulnerability documentation resulting out of a penetration test. This documentation contains for example the location and description of found vulnerabilities. To be able to find and fix a vulnerability, developers have to check this documentation. We developed a tool-based semi-automated analysis approach to locate and fix security issues by recorded execution traces. For identifying the affected source code snippets in the project code, we determine the difference between a regular and a malicious execution trace. This difference is an indicator for a potential vulnerability. As case study for this analysis we use vulnerabilities, which enable remote code execution. We implemented this approach in a software prototype named FOCUS+. This tool visualizes the traces and differences by several views such as a method call graph view. All views facilitate direct access to affected code snippets and point to the possible vulnerabilities. Thus, identified security gaps can immediately be fixed in FOCUS+.
  • Vollständige Referenz
  • BibTeX
Viertel, F. P., Karras, O. & Schneider, K., (2017). Vulnerability Recognition by Execution Trace Differentiation.   Softwaretechnik-Trends Band 37, Heft 3. Bonn: Geselllschaft für Informatik e.V.. (S. 5-7).
@inproceedings{mci/Viertel2017,
author = {Viertel, Fabien Patrick AND Karras, Oliver AND Schneider, Kurt},
title = {Vulnerability Recognition by Execution Trace Differentiation},
booktitle = {Softwaretechnik-Trends Band 37, Heft 3},
year = {2017},
editor = {} ,
pages = { 5-7 },
publisher = {Geselllschaft für Informatik e.V.},
address = {Bonn}
}
DateienGroesseFormatAnzeige
01_Vulnerability_Recognition_by_Execution_Trace_Differentiation.pdf490.0Kb PDF Öffnen

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

ISSN: 0720-8928
Datum: 2017
Sprache: en (en)
Typ: Journal Articles

Keywords

  • Code Exploit
  • Execution Trace
  • Vulnerability Analysis
Sammlungen
  • Softwaretechnik-Trends 37(3) - 2017 [16]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.