Supply chain risk management - Understanding vulnerabilities in code you buy, build, or integrate

Paul R. Croll · 2011

This paper describes the scope of the problem regarding software vulnerabilities and the current state of the practice in static code analysis for software assurance. Recommendations are made regarding the use of static analysis methods and tools during the software life. Static code analysis touch points in during life cycle reviews and challenges to automated static code analysis are also discussed.

Read the paper · More papers on PaperTik