skip to main content
10.1145/2799979.2800019acmotherconferencesArticle/Chapter ViewAbstractPublication PagessinConference Proceedingsconference-collections
abstract

A Production Model System for Detecting Vulnerabilities in the Software Source Code

Published:08 September 2015Publication History

ABSTRACT

This paper is devoted to static analysis of the software code security. We suggest using heuristic static code analysis to detect a full spectrum of vulnerabilities, including backdoors. Production rules are suggested for use to formalize heuristics for detection of vulnerabilities. We developed a conceptual system of production models for detection of a full spectrum of vulnerabilities in the software code. This paper provides examples of heuristic formalization for detection of certain vulnerabilities classified subject to CWE register. It also provides a brief statistics of application of the suggested heuristic analysis in the study of the software code security.

References

  1. Ayewah, N., Hovemeyer, D., Morgenthaler, J. D., Penix, J., Pugh, W. 2008. Using Static Analysis to Find Bugs. IEEE Software. 25, 5 (Sep./Oct. 2008), 22-29. DOI=http://dx.doi.org/10.1109/MS.2008.130. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Boulanger, J. L. (Ed.). 2011. Static Analysis of Software: The Abstract Interpretation. Wiley-ISTE.Google ScholarGoogle Scholar
  3. Chen, H., Wagner, D. 2002. MOPS: an infrastructure for examining security properties of software. In Proceedings of the 9th ACM conference on Computer and communications security. CCS'02. New York, NY, 235-244. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. Hovemeyer, D., Spacco, J., Pugh, W. 2006. Evaluating and tuning a static analysis to find null pointer bugs. CM SIGSOFT Software Engineering Notes. 31, 1 (Jan. 2006), 13-19. DOI= http://dx.doi.org/10.1145/1108768.1108798. Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. Logozzo, F., Fähndrich, M., 2008. On the Relative Completeness of Bytecode Analysis Versus Source Code Analysis. LNCS. 4959, 197-212. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. Markov, A., Luchin, D., Rautkin, Y., Tsirlov, V. 2015. Evolution of a Radio Telecommunication Hardware-Software Certification Paradigm in Accordance with Information Security Requirements, In Proceedings of the 11th International Siberian Conference on Control and Communications (Omsk, Russia, May 21-23, 2015). SIBCON-2015. IEEE, Omsk, Russia, 1-4. DOI = http://dx.doi.org/10.1109/SIBCON.2015.7147139.Google ScholarGoogle ScholarCross RefCross Ref
  7. Medvedev, N. V., Markov, A. S., Fadin, A. A. 2012. Primenenie metoda staticheskogo signaturnogo analiza dlya vyyavleniya defektov bezopasnosti veb-prilozheniy. Nauka i obrazovanie: nauchnoe izdanie MGTU im. N.E. Baumana. 9 (Sep. 2012), 21. DOI=http://dx.doi.org/10.7463/0912.0461281.Google ScholarGoogle Scholar
  8. Markov, A. S., Tsirlov, V. L. 2013. Experience in identifying vulnerabilities in software. Voprosy kiberbezopasnosti (Cybersecurity Issues. In Russia). 1(1) (Dec. 2013), 42-48.Google ScholarGoogle Scholar
  9. Reber, G., Malmquist, K., Shcherbakov, A. 2014. Mapping the Application Security Terrain. Voprosy kiberbezopasnosti (Cybersecurity Issues. In Russia). 1(2) (Jan. 2014), 36-39.Google ScholarGoogle Scholar
  10. Seacord, R. C. 2008. The CERT C Secure Coding Standard. Addison-Wesley Professional. Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. Seoa, S.-H., Guptaa, A., Sallama, A. M., Bertinoa, E., Yimb, K. 2014. Detecting mobile malware threats to homeland security through static analysis. Journal of Network and Computer Applications. 38 (Feb. 2014), 43-53. DOI= http://dx.doi.org/10.1016/j.jnca.2013.05.008. Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. Stanley, W., Laski, J. 2009. Software Verification and Analysis. Springer. Google ScholarGoogle ScholarDigital LibraryDigital Library
  13. Zhu, F., Wei, J. 2014. Static analysis based invariant detection for commodity operating systems. Computers and Security. 43, 49-63. DOI= http://dx.doi.org/10.1016/j.cose.2014.02.00.Google ScholarGoogle ScholarCross RefCross Ref

Recommendations

Comments

Login options

Check if you have access through your login credentials or your institution to get full access on this article.

Sign in
  • Published in

    cover image ACM Other conferences
    SIN '15: Proceedings of the 8th International Conference on Security of Information and Networks
    September 2015
    350 pages
    ISBN:9781450334532
    DOI:10.1145/2799979

    Copyright © 2015 Owner/Author

    Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    • Published: 8 September 2015

    Check for updates

    Qualifiers

    • abstract

    Acceptance Rates

    SIN '15 Paper Acceptance Rate34of92submissions,37%Overall Acceptance Rate102of289submissions,35%
  • Article Metrics

    • Downloads (Last 12 months)3
    • Downloads (Last 6 weeks)1

    Other Metrics

PDF Format

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader