Automated Code Review Tools for Security.

The article focuses on the use of static analysis tools for automated code review in software and computer security. Cigital's Touchpoints approach to software security is explained. The discussion includes: strategies referred to in the books "Building Secure Software: How to Avoid Security Problem...

Descripción completa

Detalles Bibliográficos
Publicado en:Computer (00189162) Vol. 41; no. 12; pp. 108 - 112
Autor principal: McGraw, Gary
Formato: Artículo
Publicado: IEEE Dec2008
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:The article focuses on the use of static analysis tools for automated code review in software and computer security. Cigital's Touchpoints approach to software security is explained. The discussion includes: strategies referred to in the books "Building Secure Software: How to Avoid Security Problems the Right Way" and "Software Security: Building Security In" for integrating security best practices into software development; the basic lexical analysis method used in Cigital's ITS4 security scanner, an open source tool; the effectiveness of network firewalls, which were introduced for computer security in the 1980s; and Web sites for the software vendors Coverity, Fortify, and Ounce Labs.