Re: Open Source Code Review
John Wilander <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
> There are a lot of the so called source code scanners. The most > popular ones are: > > splint (http://www.splint.org/), > flawfinder (http://www.dwheeler.com/flawfinder/), > its4 (http://www.cigital.com/its4/), > rats (http://www.securesw.com/rats/). But it's strongly recommended > you'll do manual inspection of your code. November 2002 we published a comparative study of the four tools mentioned above plus BOON (Buffer Overrun detectiON): "A Comparison of Publicly Available Tools for Static Intrusion Prevention" http://www.ida.liu.se/~johwi/research_publications/paper_nordsec2002_john_ wilander.pdf Links to other static analysis tools for security auditing: PScan -- http://www.striker.ottawa.on.ca/~aland/pscan/ BOON -- http://www.cs.berkeley.edu/~daw/boon/ MOPS -- http://www.cs.berkeley.edu/~daw/mops/ CQual -- http://www.cs.umd.edu/~jfoster/cqual/ February 2003 we published a comparative study of run-time defense tools (StackGuard, StackShield, ProPolice, and Libsafe/Libverify): "A Comparison of Publicly Available Tools for Dynamic Buffer Overflow Prevention" http://www.ida.liu.se/~johwi/research_publications/paper_ndss2003_john_wil ander.pdf Enjoy! Regards, John Wilander ______________________________________ John Wilander, PhD Student Computer Science, Linkoping University http://www.ida.liu.se/~johwi