首页> 外文OA文献 >Securing software : an evaluation of static source code analyzers
【2h】

Securing software : an evaluation of static source code analyzers

机译:保护软件:评估静态源代码分析器

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。
获取外文期刊封面目录资料

摘要

This thesis evaluated five static analysis tools--Polyspace C Verifier, ARCHER, BOON, Splint, and UNO--using 14 code examples that illustrated actual buffer overflow vulnerabilities found in various versions of Sendmail, BIND, and WU-FTPD. Each code example included a "BAD" case with one or more buffer overflow vulnerabilities and a "PATCHED" case without buffer overflows. The buffer overflows varied and included stack, heap, bss and data buffers; access above and below buffer bounds; access using pointers, indices, and functions; and scope differences between buffer creation and use. Detection rates for the "BAD" examples were low except for Splint and PolySpace C Verifier, which had average detection rates of 57% and 87% respectively. However, average false alarm rates, as measured using the "PATCHED" programs, were high for these two systems. The frequency of false alarms per lines of code was high for both of these tools; Splint gave on average one false alarm per 50 lines of code, and PolySpace gave on average one false alarm per 10 lines of code. This result shows that current approaches can detect buffer overflows, but that false alarm rates need to be lowered substantially.
机译:本文使用14个代码示例评估了五个静态分析工具(Polyspace C验证器,ARCHER,BOON,Slint和UNO),这些示例说明了在各个版本的Sendmail,BIND和WU-FTPD中发现的实际缓冲区溢出漏洞。每个代码示例都包括一个带有一个或多个缓冲区溢出漏洞的“ BAD”情况和一个没有缓冲区溢出的“ PATCHED”情况。缓冲区溢出各不相同,包括堆栈,堆,bss和数据缓冲区。访问缓冲区上下限;使用指针,索引和函数进行访问;缓冲区创建和使用之间的范围差异。 “ BAD”示例的检出率很低,但Splint和PolySpace C Verifier的平均检出率分别为57%和87%。但是,对于这两个系统,使用“ PATCHED”程序测得的平均误报率很高。对于这两种工具,每行代码错误警报的频率很高。 Splint每50行代码平均发出1次错误警报,而PolySpace每10行代码平均发出1次错误警报。该结果表明,当前的方法可以检测到缓冲区溢出,但是必须大大降低误报警率。

著录项

  • 作者

    Zitser Misha 1979-;

  • 作者单位
  • 年度 2003
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号