A Framework for Modeling and Detecting Security Vulnerabilities in Human-Machine Pair Programming,ERICDATA高等教育知識庫
高等教育出版
熱門: 朱丽彬  黃光男  王美玲  王善边  曾瓊瑤  崔雪娟  
高等教育出版
首頁 臺灣期刊   學校系所   學協會   民間出版   大陸/海外期刊   政府機關   學校系所   學協會   民間出版   DOI註冊服務
篇名
A Framework for Modeling and Detecting Security Vulnerabilities in Human-Machine Pair Programming
並列篇名
A Framework for Modeling and Detecting Security Vulnerabilities in Human-Machine Pair Programming
作者 Pingyan WangShaoying LiuAi LiuFatiha Zaidi
英文摘要

To detect and mitigate security vulnerabilities early in the coding phase is an important strategy for secure software development. Existing solutions typically focus on finding certain vulnerabilities in certain computer systems without giving a systematic way of handling different types of vulnerabilities. In this paper, we present a framework for systematically modeling and detecting potential security vulnerabilities during the construction of programs using a particular programming paradigm known as Human-Machine Pair Programming. The framework provides designers with a general way of modeling a class of attacks in detail, and shows how programmers can discover and fix a vulnerability in a timely manner. Specifically, our framework advocates three primary steps: (1) generating an attack tree to model a given security threat, (2) constructing vulnerability-matching patterns based on the result of the attack tree analysis, and (3) detecting corresponding vulnerabilities based on the patterns during the program construction. We also present a case study to demonstrate how it works in practice.

 

起訖頁 1129-1138
關鍵詞 Security vulnerabilitiesHuman-machine pair programmingAttack treesStatic analysis
刊名 網際網路技術學刊  
期數 202209 (23:5期)
出版單位 台灣學術網路管理委員會
DOI 10.53106/160792642022092305021   複製DOI
QR Code
該期刊
上一篇
A Multi-Trajectory Monte Carlo Sampler
該期刊
下一篇
A Study on House Price Prediction Based on Stacking-Sorted-Weighted-Ensemble Model

高等教育知識庫  新書優惠  教育研究月刊  全球重要資料庫收錄  

教師服務
合作出版
期刊徵稿
聯絡高教
高教FB
讀者服務
圖書目錄
教育期刊
訂購服務
活動訊息
數位服務
高等教育知識庫
國際資料庫收錄
投審稿系統
DOI註冊
線上購買
高點網路書店 
元照網路書店
博客來網路書店
教育資源
教育網站
國際教育網站
關於高教
高教簡介
出版授權
合作單位
知識達 知識達 知識達 知識達 知識達 知識達
版權所有‧轉載必究 Copyright2011 高等教育文化事業股份有限公司  All Rights Reserved
服務信箱:edubook@edubook.com.tw 台北市館前路 26 號 6 樓 Tel:+886-2-23885899 Fax:+886-2-23892500