Shared and Distributed Memory Parallel Security Analysis of Large-Scale Source Code and Binary Applications

Daniel J. Quinlan, Gergö Barany, Thomas Panas · OSTI OAI (U.S. Department of Energy Office of Scientific and Technical Information) · 2007

Many forms of security analysis on large scale ap-plications can be substantially automated but the size and complexity can exceed the time and mem-ory available on conventional desktop computers. Most commercial tools are understandably focused on such conventional desktop resources. This pa-per presents research work on the parallelization of security analysis of both source code and binaries within our Compass tool, which is implemented us-ing the ROSE source-to-source open compiler infras-tructure. We have focused on both shared and dis-tributed memory parallelization of the evaluation of rules implemented as checkers for a wide range of secure programming rules, applicable to desktop machines, networks of workstations and dedicated clusters. While Compass as a tool focuses on source code analysis and reports violations of an extensible set of rules, the binary analysis work uses the exact same infrastructure but is less well developed into an equivalent final tool. 1

Read the paper · More papers on PaperTik