• DocumentCode
    3037223
  • Title

    Toward the Use of Automated Static Analysis Alerts for Early Identification of Vulnerability- and Attack-prone Components

  • Author

    Gegick, M. ; Williams, Laurie

  • Author_Institution
    North Carolina State Univ., Raleigh
  • fYear
    2007
  • fDate
    1-5 July 2007
  • Firstpage
    18
  • Lastpage
    18
  • Abstract
    Extensive research has shown that software metrics can be used to identify fault- and failure-prone components. These metrics can also give early indications of overall software quality. We seek to parallel the identification and prediction of fault- and failure-prone components in the reliability context with vulnerability- and attack-prone components in the security context. Our research will correlate the quantity and severity of alerts generated by source code static analyzers to vulnerabilities discovered by manual analyses and testing. A strong correlation may indicate that automated static analyzers (ASA), a potentially early technique for vulnerability identification in the development phase, can identify high risk areas in the software system. Based on the alerts, we may be able to predict the presence of more complex and abstract vulnerabilities involved with the design and operation of the software system. An early knowledge of vulnerability can allow software engineers to make informed risk management decisions and prioritize redesign, inspection, and testing efforts. This paper presents our research objective and methodology.
  • Keywords
    program diagnostics; program testing; security of data; software metrics; software quality; software reliability; automated static analysis; failure-prone component identification; reliability context; security context; software metrics; software quality; software testing; vulnerability identification; Fault diagnosis; Inspection; Knowledge engineering; Risk analysis; Risk management; Security; Software metrics; Software quality; Software systems; Testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Monitoring and Protection, 2007. ICIMP 2007. Second International Conference on
  • Conference_Location
    San Jose, CA
  • Print_ISBN
    0-7695-2911-9
  • Electronic_ISBN
    0-7695-2911-9
  • Type

    conf

  • DOI
    10.1109/ICIMP.2007.46
  • Filename
    4271764