Automated Code Review Tools for Security.

The article focuses on the use of static analysis tools for automated code review in software and computer security. Cigital's Touchpoints approach to software security is explained. The discussion includes: strategies referred to in the books "Building Secure Software: How to Avoid Security Problem...

Descripción completa

Detalles Bibliográficos
Publicado en:Computer (00189162) Vol. 41; no. 12; pp. 108 - 112
Autor principal: McGraw, Gary
Formato: Artículo
Publicado: IEEE Dec2008
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=35777243&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 35777243
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00189162
        PUT
      jtl: Computer (00189162)
      issn: 00189162
      maglogo: N
    pubinfo:
      dt: Dec2008
      vid: 41
      iid: 12
      pid: 13605
      pub: IEEE
    artinfo:
      ui:
        35777243
        10.1109/MC.2008.514
      ppf: 108
      ppct: 4
      formats:
      tig:
        atl: Automated Code Review Tools for Security.
      aug:
        au: McGraw, Gary
      su:
        Computer security
        Coding theory
        Cigital Inc.
        Open source software
        Coverity Inc.
        Fortify Software Inc.
        Ounce Labs Inc.
        Best practices
        Computer software development
      sug:
        subj:
          Computer security
          Coding theory
          Cigital Inc.
          Open source software
          Coverity Inc.
          Fortify Software Inc.
          Ounce Labs Inc.
          Best practices
          Computer software development
      ab: The article focuses on the use of static analysis tools for automated code review in software and computer security. Cigital's Touchpoints approach to software security is explained. The discussion includes: strategies referred to in the books "Building Secure Software: How to Avoid Security Problems the Right Way" and "Software Security: Building Security In" for integrating security best practices into software development; the basic lexical analysis method used in Cigital's ITS4 security scanner, an open source tool; the effectiveness of network firewalls, which were introduced for computer security in the 1980s; and Web sites for the software vendors Coverity, Fortify, and Ounce Labs.
      pubtype: Academic Journal
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2008
    holdings:
      @attributes:
        islocal: N