Please use this identifier to cite or link to this item: https://ah.lib.nccu.edu.tw/handle/140.119/112484
題名: String analysis via automata manipulation with logic circuit representation
作者: 郁方
Wang, Hung En
Tsai, Tzung Lin
Lin, Chun Han
Yu, Fang
Jiang, Jie-Hong Roland
貢獻者: 資管系
關鍵詞: Computer aided analysis; Firmware; Formal logic; Hardware; Logic circuits; Reconfigurable hardware; World Wide Web; Attack patterns; Constraint Solving; Empirical studies; Hardware implementations; Satisfiability; Security vulnerabilities; String analysis; WEB application; Computer circuits
日期: 2016
上傳時間: 1-Sep-2017
摘要: Many severe security vulnerabilities in web applications can be attributed to string manipulation mistakes, which can often be avoided through formal string analysis. String analysis tools are indispensable and under active development. Prior string analysis methods are primarily automata-based or satisfiability-based. The two approaches exhibit distinct strengths and weaknesses. Specifically, existing automata-based methods have difficulty in generating counterexamples at system inputs to witness vulnerability, whereas satisfiability-based methods are inadequate to produce filters amenable for firmware or hardware implementation for real-time screening of malicious inputs to a system under protection. In this paper, we propose a new string analysis method based on a scalable logic circuit representation for (nondeterministic) finite automata to support various string and automata manipulation operations. It enables both counterexample generation and filter synthesis in string constraint solving. By using the new data structure, automata with large state spaces and/or alphabet sizes can be efficiently represented. Empirical studies on a large set of open source web applications and well-known attack patterns demonstrate the unique benefits of our method compared to prior string analysis tools.
關聯: Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 9779, 241-260
資料類型: conference
DOI: http://dx.doi.org/10.1007/978-3-319-41528-4_13
Appears in Collections:會議論文

Files in This Item:
File SizeFormat
241.pdf18.72 MBAdobe PDF2View/Open
Show full item record

Google ScholarTM

Check

Altmetric

Altmetric


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.