arrow
返回

Improving security using extensible lightweight static analysis

delete2002-01-01
delete257
delete
OA
AI
D
David Evans
D
David Larochelle
DOI:10.1109/52.976940delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
By David Evans and David Larochelle, pp. 42-51. Most security attacks exploit instances of well-known classes of implementation flaws. Developers could detect and eliminate many of these flaws before deploying the software, yet these problems persist with disturbing frequency-not because the security community doesn't sufficiently understand them but because techniques for preventing them have not been integrated into the software development process. This article describes an extensible tool that uses lightweight static analysis to detect common security vulnerabilities (including buffer overflows and format string vulnerabilities).

期刊

IEEE Software 封面图
IEEE Software
IF:
3
论文数:
3.2K
被引数:
3.6K

机构

暂无机构信息