IMPROVING SOFTWARE RELIABILITY AND SECURITY WITH AUTOMATED ANALYSIS

被引:0
作者
Anderson, Paul [1 ]
机构
[1] GrammaTech Inc, Ithaca, NY 14850 USA
来源
2008 IEEE MILITARY COMMUNICATIONS CONFERENCE: MILCOM 2008, VOLS 1-7 | 2008年
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Static-analysis tools that identify defects and security vulnerabilities in source and executables have advanced significantly over the last few years. A brief description of how these tools work is given. Their strengths and weaknesses in terms of the kinds of flaws they can and cannot detect are discussed. Methods for quantifying the accuracy of the analysis are described, including sources of ambiguity for such metrics. Recommendations for deployment of tools in a production setting are given.
引用
收藏
页码:1174 / 1179
页数:6
相关论文
empty
未找到相关数据