| 注册
首页|期刊导航|计算机工程与应用|JavaScript引擎漏洞检测方法综述

JavaScript引擎漏洞检测方法综述

林宏阳 彭建山 赵世斌 朱俊虎 许航

计算机工程与应用2019,Vol.55Issue(11):16-24,34,10.
计算机工程与应用2019,Vol.55Issue(11):16-24,34,10.DOI:10.3778/j.issn.1002-8331.1811-0174

JavaScript引擎漏洞检测方法综述

Survey on JavaScript Engine Vulnerability Detection

林宏阳 1彭建山 1赵世斌 1朱俊虎 1许航1

作者信息

  • 1. 数字工程与先进计算国家重点实验室,郑州 450002
  • 折叠

摘要

Abstract

JavaScript engine vulnerabilities caused by language features is one of the important threats to the security of today’s software. Attackers often use JavaScript engine vulnerabilities to demonstrate remote code execution and gain controllability of the operating system. This paper introduces the basic information of the JavaScript engine, classifies the vulnerabilities that often appear in the engine, and summarizes the basic steps and development of static and dynamic analysis methods. Then it proposes the basic framework for detecting vulnerabilities in JavaScript engines, and discusses the detection efficiency, bottlenecks and possible solutions. At last, it points out future trends and some issues.

关键词

JavaScript引擎漏洞检测/类型混淆/静态分析/模糊测试

Key words

JavaScript engine vulnerability detection/type confusion/static analysis/fuzzing

分类

信息技术与安全科学

引用本文复制引用

林宏阳,彭建山,赵世斌,朱俊虎,许航..JavaScript引擎漏洞检测方法综述[J].计算机工程与应用,2019,55(11):16-24,34,10.

基金项目

国家自然科学基金(No.61502528). (No.61502528)

计算机工程与应用

OA北大核心CSCDCSTPCD

1002-8331

访问量0
|
下载量0
段落导航相关论文