Re: Open Source Code Review

John Wilander <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
> There are a lot of the so called source code scanners. The most
> popular ones are:
> 
> splint (http://www.splint.org/),
> flawfinder (http://www.dwheeler.com/flawfinder/),
> its4 (http://www.cigital.com/its4/),
> rats (http://www.securesw.com/rats/). But it's strongly recommended
> you'll do manual inspection of your code. 

November 2002 we published a comparative study of the four tools mentioned
above plus BOON (Buffer Overrun detectiON):

"A Comparison of Publicly Available Tools for Static Intrusion Prevention"
http://www.ida.liu.se/~johwi/research_publications/paper_nordsec2002_john_
wilander.pdf

Links to other static analysis tools for security auditing:
PScan -- http://www.striker.ottawa.on.ca/~aland/pscan/
BOON -- http://www.cs.berkeley.edu/~daw/boon/
MOPS -- http://www.cs.berkeley.edu/~daw/mops/
CQual -- http://www.cs.umd.edu/~jfoster/cqual/

February 2003 we published a comparative study of run-time defense tools
(StackGuard, StackShield, ProPolice, and Libsafe/Libverify):

"A Comparison of Publicly Available Tools for Dynamic Buffer Overflow
Prevention"
http://www.ida.liu.se/~johwi/research_publications/paper_ndss2003_john_wil
ander.pdf

   Enjoy!
   Regards, John Wilander

______________________________________
John Wilander, PhD Student
Computer Science, Linkoping University
http://www.ida.liu.se/~johwi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.