| Sumario: | The article focuses on the use of static analysis tools for automated code review in software and computer security. Cigital's Touchpoints approach to software security is explained. The discussion includes: strategies referred to in the books "Building Secure Software: How to Avoid Security Problems the Right Way" and "Software Security: Building Security In" for integrating security best practices into software development; the basic lexical analysis method used in Cigital's ITS4 security scanner, an open source tool; the effectiveness of network firewalls, which were introduced for computer security in the 1980s; and Web sites for the software vendors Coverity, Fortify, and Ounce Labs.
|