• DocumentCode
    2256398
  • Title

    Software assurance with samate reference dataset, tool standards, and studies

  • Author

    Black, Paul E.

  • Author_Institution
    Nat. Inst. of Stadards & Technol., Gaithersburg
  • fYear
    2007
  • fDate
    21-25 Oct. 2007
  • Abstract
    Today´s avionics systems depend more and more on software from many sources: vendors, subcontractors, in-house, and open source. System interactions are exposed to external agents in contexts from air-to-ground links to OS patches downloaded via the Internet. This is a huge amount of software with the risk of attack from distant global sites. Yet users need assurance that the software will work and not create security problems. We focus on NIST´s Software Assurance Metrics And Tool Evaluation (SAMATE) project and its contribution. SAMATE is developing specifications, metrics, and automated test suites for software assurance tools. For instance, source code security analyzers can help developers produce software with fewer security flaws. They can also help identify malicious code and poor coding practices that lead to vulnerabilities. The project´s publicly available reference dataset, the SRD, contains more than 1800 flawed (and fixed!) program examples to help evaluate software assurance tools and algorithms. These metrics and reference datasets help purchasers confirm tool vendors´ claims. We also study the assurance impact of tool use, methods, and techniques.
  • Keywords
    aerospace engineering; avionics; formal specification; security of data; software metrics; software performance evaluation; software quality; NIST SAMATE project; avionics systems; software assurance metrics; software tool evaluation; source code security; Aerospace electronics; Automatic testing; Data security; Internet; NIST; Open source software; Software standards; Software testing; Software tools; Subcontracting;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Digital Avionics Systems Conference, 2007. DASC '07. IEEE/AIAA 26th
  • Conference_Location
    Dallas, TX
  • Print_ISBN
    978-1-4244-1108-5
  • Electronic_ISBN
    978-1-4244-1108-5
  • Type

    conf

  • DOI
    10.1109/DASC.2007.4391957
  • Filename
    4391957