Journal of Software:2018.29(1):42-68

(中国科学院 信息工程研究所 网络测评技术重点实验室, 北京 100195;北京市网络安全技术重点实验室(中国科学院 信息工程研究所), 北京 100195;中国科学院 软件研究所 可信计算与信息保障实验室, 北京 100190;复旦大学 软件学院, 上海 201203;计算机科学国家重点实验室(中国科学院 软件研究所), 北京 100190)
Software and Cyber Security-A Survey
LIU Jian,SU Pu-Rui,YANG Min,HE Liang,ZHANG Yuan,ZHU Xue-Yang,LIN Hui-Min
(Key Laboratory of Network Assessment Technology, Institute of Information Engineering, The Chinese Academy of Sciences, Beijing 100195, China;Beijing Key Laboratory of Network Security Technology(Institute of Information Engineering, The Chinese Academy of Sciences), Beijing 100195, China;Trusted Computing and Information Assurance Laboratory, Institute of Software, The Chinese Academy of Sciences, Beijing 100190, China;School of Software, Fudan University, Shanghai 201203, China;State Key Laboratory of Computer Science(Institute of Software, The Chinese Academy of Sciences), Beijing 100190, China)
Received:December 22, 2016    Revised:February 08, 2017
> 中文摘要: 互联网已经渗入人类社会的各个方面,极大地推动了社会进步.与此同时,各种形式的网络犯罪、网络窃密等问题频繁发生,给社会和国家安全带来了极大的危害.网络安全已经成为公众和政府高度关注的重大问题.由于互联网的大量功能和网络上的各种应用都是由软件实现的,软件在网络安全的研究与实践中扮演着至关重要的角色.事实上,几乎所有的网络攻击都是利用系统软件或应用软件中存在的安全缺陷实施的.研究新形势下的软件安全问题日益迫切.从恶意软件、软件漏洞和软件安全机制这3个方面综述了国内外研究现状,进而分析软件生态系统面临的全新安全挑战与发展趋势.
Abstract:The Internet has penetrated into all aspects of human society and has greatly promoted social progress. At the same time, various forms of cybercrimes and network theft occur frequently, bringing great harm to our society and national security. Cyber security has become a major concern to the public and the government. As a large number of Internet functionalities and applications are implemented by software, software plays a crucial role in cyber security research and practice. In fact, almost all cyberattacks were carried out by exploiting vulnerabilities in system software or application software. It is increasingly urgent to investigate the problems of software security in the new age. This paper reviews the state of the art of malware, software vulnerabilities and software security mechanism, and analyzes the new challenges and trends that the software ecosystem is currently facing.
基金项目:国家自然科学基金(61572483,61572481,61602123,61572478,U1636204,61602457);上海市青年科技英才扬帆计划(16YF1400800) 国家自然科学基金(61572483,61572481,61602123,61572478,U1636204,61602457);上海市青年科技英才扬帆计划(16YF1400800)
Foundation items:National Natural Science Foundation of China (61572483, 61572481, 61602123, 61572478, U1636204, 61602457); Shanghai Sailing Program (16YF1400800)
