Your opinion on a valuable and feasible goal for a new source code auditing tool

Holger Peine <[email protected]>
Newsgroups gmane.comp.security.programming
Organization Fraunhofer IESE, Kaiserslautern, Germany
Message-ID <[email protected]>
Hello everyone,

we are a research and technology transfer instititue in Germany, 
and some of us have recently started to work on secure software
development (we have a long tradition of security analysis of 
systems, processes, and some software). One item on our agenda
is to develop a source code auditing tool (we also have experience
with building non-security-related reverse engineering tools).

However, we are not really sure what type of security property of
a program could be both clearly relevant in practice as well as
automatically determinable from the source code (most preferably
without requiring special annotations!) with an effort of (say) 6 person 
months of work.

Buffer overflow detection in C programs is the first thing that
comes to mind, but there are already various efforts in this
direction (source code scanners and other things like compiler
support).   Another idea we have come up with is building an input 
validation checker similar to Perl's taint mode other languages 
(most probably Java, C++, or C). Do you think that taint checking
would cover a noteworthy share of _pratical_ software security bugs?
Or what else would you suggest instead?

We are aware of tools like flawfinder, ITS4, RATS, MOPS, Splint.

Thank you for your opinion,
Holger Peine

-- 
Dr. Holger Peine
Fraunhofer IESE, Kaiserslautern, Germany
Phone +49-6301-707-134, Fax -209 (shared)
www.iese.fraunhofer.de/Staff/peine -- PGP key on request or via pgp.mit.edu
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.