Demonstration of COSAK static analysis tools

D. DaCosta, Christine Dahn, Spiros Mancoridis, Vassilis Prevelakis · 2004

A software vulnerability is a fault in the specification, implementation, or configuration of a software system whose execution can violate an explicit or implicit security policy. Users typically focus on the functionality of software rather than its security posture. Hence, vulnerabilities often escape their attention until the software is exploited by specially written malicious code. Code auditing is one solution which has been tried with some success in systems such as the OpenBSD operating system. Code audits involve the review of source code by experts in search of vulnerabilities. These audits are reoccurring, namely each revision of the software requires reexamination, and expensive because code audits are labor intensive. Auditors would benefit from a tool which enables them to focus their attention on high-risk areas, thus reducing the amount of code that needs to be audited. The article shows how the tools developed at Drexel University can be used to direct the attention of code auditors to those components that have a high likelihood of being vulnerable.

Read the paper · More papers on PaperTik