Detecting interger flaws by type-qualified system dependence graph

Qingxian Wang, Pla Information · Jisuanji yingyong yanjiu · 2008

However currently,most of the source code auditing tools have limitation in detecting integer flaws,which can only detect integer overflow.For this,combining the theory of type qualifier and the checking model of system dependence graph(SDG),this paper presented a type-qualified SDG(QSDG) checking model which could detect most of the potential integer flaws in C codes and recognize their types which defined eight types in term of their cause.Compared with only using isomorphism algorithm in SDG checking model,the method checking QSDG after type inferencing can reduce time cost.

Read the paper · More papers on PaperTik