期刊文献+

基于静态检测工具的源代码安全缺陷检测研究 被引量:11

Research on source code safety defects based on static test tools
下载PDF
导出
摘要 针对已有的使用单个静态检测工具进行源代码安全缺陷检测存在的漏报率和误报率很高的问题,提出了一种基于多种静态检测工具的检测方法。该方法通过对多种工具的检测结果进行统计分析,有效地降低了漏报率和误报率。设计和实现了一个可扩展的源代码静态分析工具平台,并通过实验表明,相对于单个工具的检测结果而言,该平台明显降低了漏报率和误报率。 To cope with the problem of high false negatives and false positives in source code static analysis methods with a static test tool,this paper presented a static analysis detection method for safety defects detection based on several static test tools.This method made statistical analysis on the outcome of different static test tools,which greatly decreased the false negatives and false positives.It designed and implemented a scalable source code static analysis tool platform,and it was proved by experiment that this platform has a better performance with lower false negatives and false positives compared with one single static test tool.
出处 《计算机应用研究》 CSCD 北大核心 2011年第8期2997-2998,3021,共3页 Application Research of Computers
基金 国家"863"计划资助项目(2009AA01Z435 2009AA01Z403)
关键词 静态检测工具 源代码 安全缺陷 统计分析 static test tools source code safety defects statistical analysis
  • 相关文献

参考文献8

  • 1BRIAN C. Static analysis for security[J]. IEEE Security & Privacy,2004,7(4) :32-36.
  • 2DAVID E,JOHN G, JIM H. LCLint:a tool for using specifications to check code [ C ]//Proc of SIGSOFT Symposium on the Foundations of Software Engineering. 1994.
  • 3JOHN V. Its4:a static vulnerability scanner for C and C + + code [ C]//Proc of Annual Computer Security Applications Conference. 2000.
  • 4Rough auditing tool for security [ EB/OL]. (2006). http ://www. fortifysoftware, corn/security-resources/Dec.
  • 5Flawfinder [ EB/OL]. (2006- 12 ). http://www, dwheeler, corn/ flawfinder.
  • 6RAJEE V, EUGENE H, JAN V. FaultMiner: discovering unknown software defects using static analysis and data mining [ C ]//Proc of CERIASTR. 2006.
  • 7Oink[ EB/OL]. (2006-12). http: //oink. me. uk/.
  • 8DAVID P, RICCARDO S. Comparing lexical analysis is tools for buffer overflow detection in network software[ C ] HProc of the 1st In ternational Conference on Communication System Software and Mid- dleware. 2006.

同被引文献44

引证文献11

二级引证文献9

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部