loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
30th Annual International Computer Software and Applications Conference (COMPSAC'06)
An Ontology-Based Approach to Software Comprehension - Reasoning about Security Concerns
Chicago, Illinois
September 17-September 21
ISBN: 0-7695-2655-1
Yonggang Zhang, Concordia University, Canada
Juergen Rilling, Concordia University, Canada
Volker Haarslev, Concordia University, Canada
There exists a large variety of techniques to detect and correct software security vulnerabilities at the source code level, including human code reviews, testing, and static analysis. In this article, we present a static analysis approach that supports both the identification of security flaws and the reasoning about security concerns. We introduce an ontology-based program representation that lets security experts and programmers specify their security concerns as part of the ontology. Within our tool implementation, we support complex queries on the underlying program model using either predefined or user-defined concepts and relations. Queries regarding security concerns, such as exception handling, object accessibility etc. are demonstrated in order to show the applicability and flexibility of our approach.
Citation:
Yonggang Zhang, Juergen Rilling, Volker Haarslev, "An Ontology-Based Approach to Software Comprehension - Reasoning about Security Concerns," compsac, vol. 1, pp.333-342, 30th Annual International Computer Software and Applications Conference (COMPSAC'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.