• DocumentCode
    2791392
  • Title

    A Rule-based Security Auditing Tool for Software Vulnerability Detection

  • Author

    Lee, Moohun ; Cho, Sunghoon ; Jang, Changbok ; Park, Heeyong ; Choi, Euiin

  • Author_Institution
    Dept. of Comput. Eng., Hannam Univ.
  • Volume
    2
  • fYear
    2006
  • fDate
    9-11 Nov. 2006
  • Firstpage
    505
  • Lastpage
    512
  • Abstract
    We can use information and software of various forms without being restricted for place and time if ubiquitous computing age comes. However, its reverse function is causing security problems such as outflow of personal information, hacking, diffusion of virus. Specially, dissemination of software that has malicious purpose in ubiquitous computing environment causes serious damage. We have studied about malicious code detection and software vulnerability detection tool to prevent this. But, existent detection tools are not suited to general software, because they are limitative in specification area. In addition, they can not detect a newly appeared malicious code. We must update pattern of new malicious code, because they use a simple pattern matching technique. In this paper, we propose rule-based security auditing tool that analyzes structure of target code to solve these problems, define this as rule, and detect malicious codes and software vulnerabilities. Proposed auditing tool can construct secure ubiquitous computing environment, because it will be used by a common software audit tool that detects malicious codes and software vulnerabilities at the same time
  • Keywords
    invasive software; knowledge based systems; pattern matching; software tools; ubiquitous computing; malicious code detection; pattern matching technique; rule-based security auditing tool; software vulnerability detection; ubiquitous computing; Computer crime; Computer security; Information security; Pattern matching; Pervasive computing; Software design; Software engineering; Software safety; Software tools; Ubiquitous computing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Hybrid Information Technology, 2006. ICHIT '06. International Conference on
  • Conference_Location
    Cheju Island
  • Print_ISBN
    0-7695-2674-8
  • Type

    conf

  • DOI
    10.1109/ICHIT.2006.253653
  • Filename
    4021258