(Enter summary)
Abstract: In recent years researchers have presented several tools for statically checking security properties of C code. But they all (currently) focus on one or two categories of security properties each. We have proposed dependence graphs decorated with type-cast and range information as a more generic formalism allowing both for visual communication with the programmer and static analysis checking several security properties at once. Our prototype tool GraphMatch currently checks code for input... (Update)
Active bibliography (related documents): More All
2.9: Policy and Implementation Assurance for Software Security - Wilander (2005)
(Correct)
2.7: Modeling and Visualizing Security Properties of Code Using.. - Wilander (2005)
(Correct)
0.3: A Comparison of Publicly Available Tools for Static.. - Wilander, Kamkar (2002)
(Correct)
Similar documents based on text:
0.0: Unknown -
(Correct)
BibTeX entry: (Update)
@inproceedings{ wilander-pattern,
author = "John Wilander and Pia Fak",
title = "Pattern Matching Security Properties of Code using Dependence Graphs",
booktitle="Proceedings of the 1st International Workshop on Code Based Software Security Assessments (CoBaSSA 2005)",
year = "2005",
month = "November",
address = "Pittsburgh, Pennsylvania",
url = "citeseer.ist.psu.edu/740927.html",
url = "http://www.ida.liu.se/~johwi/research_publications/paper_cobassa2005_wilander_fak.pdf" }
Citations (may not include all citations):
4212
Computers and Intractability : A Guide to the Theory of NP-C.. (context) - Garey, Johnson - 1979
390
Interprocedural slicing using dependence graphs
- Horwitz, Reps et al. - 1990
265
Program slicing (context) - Weiser - 1981
186
The program dependence graph in a software development envir.. (context) - Ottenstein, Ottenstein - 1984
157
Proving the correctness of multiprocess programs (context) - Lamport - 1977
58
MOPS: An infrastructure for examining security properties of..
- Chen, Wagner - 2002
46
Using programmer written compiler extensions to catch securi..
- Ashcraft, Engler - 2002
12
Improving computer security using extended static checking
- Chess - 2002
8
Tracking pointers with path and context sensitivity for bug ..
- Livshits, Lam - 2003
6
Some lessons from using static analysis and software model c..
- Musuvathi, Engler - 2003
3
Cqual: A tool for adding type qualifiers to C (context) - Foster, Johnson et al. - 2003
3
Automatic detection of implicit type cast errors in C (context) - Chen, Rudiak-Gould et al. - 2002
3
A case study in detecting software security vulnerabilities .. (context) - Weber, Shah et al. - 2001
3
Reviewing code for integer manipulation vulnerabilities (context) - Howard
3
Phrack Magazine httpwww (context) - integer, Magazine et al. - 2002
3
Secure programming for Linux and Unix HOWTO v (context) - Wheeler - 2003
3
A comparative study of publicly available tools for static i.. (context) - Wilander, Kamkar - 2002
2
Modeling and visualizing security properties of code using d..
- Wilander - 2005
Documents on the same site (http://www.ida.liu.se/~johwi/research_publications/index_citeseer.html): More
A Comparison of Publicly Available Tools for Dynamic Buffer.. - Wilander, Kamkar (2003)
(Correct)
Policy and Implementation Assurance for Software Security - Wilander (2005)
(Correct)
Modeling and Visualizing Security Properties of Code Using.. - Wilander (2005)
(Correct)
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC