【24h】

Integrity Static Analysis of COTS/SOUP

机译:COTS / SOUP的完整性静态分析

获取原文
获取原文并翻译 | 示例

摘要

This paper describes the integrity static analysis approach developed to support the justification of commercial off-the-shelf software (COTS) used in a safety-related system. The static analysis was part of an overall software qualification programme, which also included the work reported in our paper presented at Safecomp 2002. Integrity static analysis focuses on unsafe language constructs and "covert" flows, where one thread can affect the data or control flow of another thread. The analysis addressed two main aspects: the internal integrity of the code (especially for the more critical functions), and the intra-component integrity, checking for covert channels. The analysis process was supported by an aggregation of tools, combined and engineered to support the checks done and to scale as necessary. Integrity static analysis is feasible for industrial scale software, did not require unreasonable resources and we provide data that illustrates its contribution to the software qualification programme.
机译:本文描述了完整性静态分析方法,该方法旨在支持在安全相关系统中使用的商用现货软件(COTS)的合理性。静态分析是整体软件认证计划的一部分,该计划还包括我们在Safecomp 2002上发表的论文中报告的工作。完整性静态分析着眼于不安全的语言构造和“隐式”流程,其中一个线程可以影响数据或控制流程。另一个线程。该分析涉及两个主要方面:代码的内部完整性(尤其是对于更关键的功能)以及组件内部的完整性(检查隐蔽通道)。分析过程由一系列工具支持,这些工具经过组合和设计可支持完成的检查并根据需要进行扩展。完整性静态分析对于工业规模的软件是可行的,不需要不合理的资源,我们提供的数据说明了其对软件资格认证计划的贡献。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号