Loading...
Please wait, while we are loading the content...
Similar Documents
Proceedings of the First International Workshop on Code Based Software Security Assessments — CoBaSSA 2005 — November 7 th 2005
| Content Provider | Semantic Scholar |
|---|---|
| Author | Wilander, John Walenstein, Andrew Lakhotia, Arun |
| Copyright Year | 2005 |
| Abstract | In recent years researchers have presented several tools for statically checking security properties of C code. But they all (currently) focus on one or two categories of security properties each. We have proposed dependence graphs decorated with type-cast and range information as a more generic formalism allowing both for visual communication with the programmer and static analysis checking several security properties at once. Our prototype tool GraphMatch currently checks code for input validation flaws. But several research questions are still open. Most importantly we need to address the complexity of our algorithm for pattern matching graphs, the accuracy of our security models, and the generality of our formalism. Other questions regard the impact of security property visualization and heuristics for ranking of potential flaws found. |
| File Format | PDF HTM / HTML |
| Alternate Webpage(s) | https://www.cs.drexel.edu/~spiros/teaching/CS675/slides/cobassa2005.pdf |
| Alternate Webpage(s) | http://swerl.tudelft.nl/leon/cobassa2005/cobassa2005-proceedings.pdf |
| Alternate Webpage(s) | http://www.cs.drexel.edu/~spiros/teaching/CS675/slides/cobassa2005.pdf |
| Language | English |
| Access Restriction | Open |
| Content Type | Text |
| Resource Type | Proceeding |