loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
31st EUROMICRO Conference on Software Engineering and Advanced Applications
Software Security Analysis - Execution Phase Audit
Porto, Portugal
August 30-September 03
ISBN: 0-7695-2431-1
Bengt Carlsson, School of Engineering, Blekinge Institute of Technology, Ronneby, SWEDEN
Dejan Baca, Ericsson AB ,Karlskrona, SWEDEN

Code revision of a leading telecom product was performed, combining manual audit and static analysis tools. On average, one exploitable vulnerability was found for every 4000 lines of code. Half of the located threats in the product were buffer overflows followed by race condition, misplaced trust, and poor random generators. Static analysis tools were used to speed up the revision process and to integrate security tests into the overall project process. The discussion analyses the effectiveness of automatic tools for auditing software. Furthermore, the incorporation of the software security analysis into the development process, and the results and costs of the security analysis is discussed. From the initial 42 workdays used for finding all vulnerabilities, approximately 16 days were needed for finding and correcting 91,5 % of the vulnerabilities. So, proportionally small investments improve the program code security by integrating an automatic auditing tool into the ordinary execution of source code revision.

Citation:
Bengt Carlsson, Dejan Baca, "Software Security Analysis - Execution Phase Audit," euromicro, pp.240-247, 31st EUROMICRO Conference on Software Engineering and Advanced Applications, 2005
Usage of this product signifies your acceptance of the Terms of Use.