Application security code analysis: a step towards software assurance. (22nd June 2009)
- Record Type:
- Journal Article
- Title:
- Application security code analysis: a step towards software assurance. (22nd June 2009)
- Main Title:
- Application security code analysis: a step towards software assurance
- Authors:
- Rawat, Sanjay
Saxena, Ashutosh - Abstract:
- The last few years have witnessed a rapid growth in cyber attacks, with daily new vulnerabilities being discovered in computer applications. Various security-related technologies, e.g., anti-virus programs, Intrusion Detection Systems (IDSs)/Intrusion Prevention Systems (IPSs), firewalls, etc., are deployed to minimise the number of attacks and incurred losses. However, such technologies are not enough to completely eliminate the attacks to some extent; they can only minimise them. Therefore, software assurance is becoming a priority and an important characteristic of the software development life cycle. Application code analysis is gaining importance, as it can help in writing safe code during the development phase by detecting bugs that may lead to vulnerabilities. As a result, tremendous research on code analysis has been carried out by industry and academia and there exist many commercial and open source tools and approaches for this purpose. These have their own pros and cons. Therefore, the main objective of this article is to explore the state-of-the-art in code analysis and a few major tools which benefit not only security professionals, but also novice Information Technology (IT) professionals. We study the tools and techniques under the basic four types of analysis (Static Source Code (SSC), Static Binary Code (SBC), Dynamic Source Code (DSC) and Dynamic Binary Code (DBC) analysis) and briefly discuss them.
- Is Part Of:
- International journal of information and computer security. Volume 3:Number 1(2009)
- Journal:
- International journal of information and computer security
- Issue:
- Volume 3:Number 1(2009)
- Issue Display:
- Volume 3, Issue 1 (2009)
- Year:
- 2009
- Volume:
- 3
- Issue:
- 1
- Issue Sort Value:
- 2009-0003-0001-0000
- Page Start:
- 86
- Page End:
- 110
- Publication Date:
- 2009-06-22
- Subjects:
- security vulnerability -- application code analysis -- data flow -- taint analysis -- binary code instrumentation -- code debugging -- software assurance -- information security -- computer security -- static source code -- static binary code -- dynamic source code -- dynamic binary code
Computer security -- Periodicals
Information systems management -- Security measures -- Periodicals
Computer networks -- Security measures -- Periodicals
Information technology -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.inderscience.com/browse/index.php?journalCODE=ijics ↗
http://www.inderscience.com/ ↗ - Languages:
- English
- ISSNs:
- 1744-1765
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 8684.xml