TUHH Open Research
Help
  • Log In
    New user? Click here to register.Have you forgotten your password?
  • English
  • Deutsch
  • Communities & Collections
  • Publications
  • Research Data
  • People
  • Institutions
  • Projects
  • Statistics
  1. Home
  2. TUHH
  3. Publication References
  4. The seven turrets of Babel: a taxonomy of LangSec errors and how to expunge them
 
Options

The seven turrets of Babel: a taxonomy of LangSec errors and how to expunge them

Publikationstyp
Conference Paper
Date Issued
2017-02-06
Sprache
English
Author(s)
Momot, Falcon Darkstar  
Bratus, Sergey  
Hallberg, Sven Moritz  
Patterson, Meredith L.  
Institut
Sicherheit in verteilten Anwendungen E-15  
TORE-URI
http://hdl.handle.net/11420/4733
Start Page
45
End Page
52
Article Number
7839788
Citation
Proceedings - 2016 IEEE Cybersecurity Development, SecDev 2016: 7839788 45-52 (2017-02)
Contribution to Conference
IEEE Cybersecurity Development, SecDev 2016  
Publisher DOI
10.1109/SecDev.2016.019
Scopus ID
2-s2.0-85014872403
Publisher
IEEE
Input-handling bugs share two common patterns: insufficient recognition, where input-checking logic is unfit to validate a program's assumptions about inputs, %leading to the code acting on invalid inputs, and parser differentials, wherein two or more components of a system fail to interpret input equivalently. We argue that these patterns are artifacts of avoidable weaknesses in the development process and explore these patterns both in general and via recent CVE instances. We break ground on defining the input-handling code weaknesses that should be actionable findings and propose a refactoring of existing CWEs to accommodate them. We propose a set of new CWEs to name such weaknesses that will help code auditors and penetration testers precisely express their findings of likely vulnerable code structures.
Subjects
CWEs
LangSec
secure parsing
DDC Class
600: Technik
TUHH
Weiterführende Links
  • Contact
  • Send Feedback
  • Cookie settings
  • Privacy policy
  • Impress
DSpace Software

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science
Design by effective webwork GmbH

  • Deutsche NationalbibliothekDeutsche Nationalbibliothek
  • ORCiD Member OrganizationORCiD Member Organization
  • DataCiteDataCite
  • Re3DataRe3Data
  • OpenDOAROpenDOAR
  • OpenAireOpenAire
  • BASE Bielefeld Academic Search EngineBASE Bielefeld Academic Search Engine
Feedback