首页 | 本学科首页   官方微博 | 高级检索  
     

基于D-S证据理论的嵌入式固件Web代码静态漏洞检测技术
引用本文:王思琪,缪思薇,张小玲,石志强,卢新岱.基于D-S证据理论的嵌入式固件Web代码静态漏洞检测技术[J].北京邮电大学学报,2019,42(5):91-99.
作者姓名:王思琪  缪思薇  张小玲  石志强  卢新岱
作者单位:中国科学院信息工程研究所,北京100093;中国科学院大学 网络空间安全学院, 北京100049;中国电力科学研究院有限公司,北京,100192;国网浙江省电力有限公司电力科学研究院,杭州,310014
基金项目:国家电网有限公司总部科技项目(52110418001K)
摘    要:固件的漏洞挖掘和检测主要包含基于虚拟仿真的动态漏洞挖掘与检测技术和基于逆向工程的静态白盒审计技术等,其存在仿真率低或误报率高等问题,为此,提出了一种基于多维度特征的固件Web漏洞检测方法,利用多维度特征、多层级处理技术和基于D-S证据理论的漏洞推理规则,针对固件Web中常见的各类漏洞进行有效检测,并能降低漏洞检测误报率.

关 键 词:固件Web  静态分析  漏洞检测  多维度特征  D-S证据理论
收稿时间:2018-11-10

Static Vulnerability Detection Technology for the Embedded Firmware Web Code Based on D-S Evidence Theory
WANG Si-qi,MIAO Si-wei,ZHANG Xiao-ling,SHI Zhi-qiang,LU Xin-dai.Static Vulnerability Detection Technology for the Embedded Firmware Web Code Based on D-S Evidence Theory[J].Journal of Beijing University of Posts and Telecommunications,2019,42(5):91-99.
Authors:WANG Si-qi  MIAO Si-wei  ZHANG Xiao-ling  SHI Zhi-qiang  LU Xin-dai
Affiliation:1. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China;
2. School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China;
3. China Electric Power Research Institute, Beijing 100192, China;
4. State Grid Zhejiang Electric Power Research Institute, Hangzhou 310014, China
Abstract:Currently, vulnerabilities mining and detection for firmware mainly include dynamic analysis which based on virtual simulation and static auditing which based on reverse engineering. These techniques may have low simulation rate and high false positive rate. Proposing a method based on multi-dimensional features for detection of firmware web vulnerabilities. This method can detect common Web vulnerabilities in firmware effectively and lower the false positive rate by using multi-dimensional features, multi-level preprocessing and vulnerabilities reasoning models based on D-S evidence theory.
Keywords:firmware web  static analysis  vulnerability detection  multi-dimensional feature  D-S evidence theory  
本文献已被 万方数据 等数据库收录!
点击此处可从《北京邮电大学学报》浏览原始摘要信息
点击此处可从《北京邮电大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号