收稿日期: 2008-06-28
修回日期: 2008-11-06
网络出版日期: 2009-05-15
基金资助
国家自然科学基金(60573048,60773135,90718007)和国家863计划项目(2007AA01Z427,2007AA01Z450)资助
Lexical analysis in source code analysis
Received date: 2008-06-28
Revised date: 2008-11-06
Online published: 2009-05-15
肖锋 , 张玉清 . 源码审核技术中的词法分析[J]. 中国科学院大学学报, 2009 , 26(3) : 408 -414 . DOI: 10.7523/j.issn.2095-6134.2009.3.016
Source code analysis means detecting and correcting the security vulnerabilities of these software in time during the coding stage, and lexical analysis is one of the important techniques in it. In this paper, we manage to detailedly analyze the implement process of lexical analysis, improve dangerous function database, optimize the method of features analysis,and particularly introduce Bayesian theory to the lexical analysis. In addition, a lexical analysis tool SSCAN is designed and implemented successfully, which is proved to have higher integrity and accuracy than mainstream open-source lexical analysis software Flawfinder and Rats by several tests.
Key words: source code analysis; lexical analysis; features analysis; Bayesian theory
[1] Heffley J, Meunier P. Can source code auditing software identify common vulnerabilities and beused to evaluate software security. In: HICSS 2004. Hawaii, Jan, 2004
[2] Davide Pozza, Luca Durante. Comparing lexical analysis tools for buffer overflow detection in ne-twork software. In: First International Conference on Communication System Software and Middleware(Comsware 2006). 2006.1~7
[3] FlawFinder Home Page. http://www.dwheeler.com/flawfinder/. 2008-6-25
[4] ITS4: A static vulnerability scanner for C and C+ + code. http://www.cigital.com/papers/downlo-ad/its4.pdf. 2008-6-25
[5] James, Berger. 贾乃光译.统计决策论及贝叶斯分析.北京: 中国统计出版社, 1998
/
| 〈 |
|
〉 |