首页> 外文会议>2018 Ivannikov Memorial Workshop >Design and Development of Svace Static Analyzers
【24h】

Design and Development of Svace Static Analyzers

机译:Svace静态分析仪的设计与开发

获取原文
获取原文并翻译 | 示例

摘要

Static analysis became the mainstream technology that is widely used in secure development lifecycles. As such it is covered by a lot of research works highlighting many diverse aspects. We would like to make this paper a single place that focuses on two important questions. First, it is a very long road to travel for a tool to be deployed in production, and the technology and design that actually worked is of interest. Second, once the tool has been made, it needs to be pushed further both with the evolutional approach of gradually improving analysis algorithms and with exploring completely new ideas, yet this task is not easy as inviting directions are many. This paper presents our view for the above problems in the context of a static analysis that strives to be fully automatic, scalable to modern computing systems and generating good quality warnings. We derive the discussion from our experience put into the Svace static analyzers that have been made at ISP RAS and deployed to various production development environments.
机译:静态分析已成为安全开发生命周期中广泛使用的主流技术。因此,它被许多突出许多不同方面的研究工作所涵盖。我们希望使本文成为一个集中讨论两个重要问题的地方。首先,要在生产中部署工具要走很长的路要走,而实际起作用的技术和设计很有趣。其次,一旦制作出该工具,就需要通过逐步改进分析算法的进化方法以及探索全新思路来进一步推动该工具的发展,但是由于邀请方向很多,因此这项任务并不容易。本文在静态分析的背景下提出了上述问题的观点,该分析力争实现全自动,可扩展到现代计算系统并生成高质量的警告。我们根据在ISP RAS上制作并部署到各种生产开发环境的Svace静态分析器中的经验进行讨论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号