2004IEEE Security & PrivacyRequires access

Static analysis for security

B. Chess, Gary McGraw

Open publisher page 428 citations

Abstract

All software projects are guaranteed to have one artifact in common $source code. Together with architectural risk analysis, code review for security ranks very high on the list of software security best practices. We look at how to automate source-code security analysis with static analysis tools.

About this research paper

What this paper is about

All software projects are guaranteed to have one artifact in common $source code. Together with architectural risk analysis, code review for security ranks very high on the list of software security best practices. We look at how to automate source-code security analysis with static analysis tools.

Why it matters

OpenAlex reports 428 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

All software projects are guaranteed to have one artifact in common $source code. Together with architectural risk analysis, code review for security ranks very high on the list of software security best practices. We look at how to automate source-code security analysis with static analysis tools.

Key concepts: Software security assurance, Computer science, Static program analysis, Artifact (error), Static analysis, Source code, Security analysis, Code (set theory)

Related papers

Back to paper searchBrowse research topicsOriginal source
Static analysis for security — Research Paper | ScholarLens