Invention Grant
- Patent Title: Global variable security analysis
- Patent Title (中): 全局变量安全性分析
-
Application No.: US12951435Application Date: 2010-11-22
-
Publication No.: US08656496B2Publication Date: 2014-02-18
- Inventor: Shay Artzi , Ryan Berg , John Peyton , Marco Pistoia , Manu Sridharan , Takaaki Tateishi , Omer Tripp , Robert Wiener
- Applicant: Shay Artzi , Ryan Berg , John Peyton , Marco Pistoia , Manu Sridharan , Takaaki Tateishi , Omer Tripp , Robert Wiener
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporations
- Current Assignee: International Business Machines Corporations
- Current Assignee Address: US NY Armonk
- Agency: Harrington & Smith
- Agent Louis J. Percello
- Main IPC: G06F11/07
- IPC: G06F11/07 ; G06F9/455

Abstract:
A method includes determining selected global variables in a program for which flow of the selected global variables through the program is to be tracked. The selected global variables are less than all the global variables in the program. The method includes using a static analysis performed on the program, tracking flow through the program for the selected global variables. In response to one or more of the selected global variables being used in security-sensitive operations in the flow, use is analyzed of each one of the selected global variables in a corresponding security-sensitive operation. In response to a determination the use may be a potential security violation, the potential security violation is reported. Apparatus and computer program products are also disclosed.
Public/Granted literature
- US20120131670A1 Global Variable Security Analysis Public/Granted day:2012-05-24
Information query