Your opinion on a valuable and feasible goal for a new source code auditing tool
Holger Peine <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Organization | Fraunhofer IESE, Kaiserslautern, Germany |
| Message-ID | <[email protected]> |
Hello everyone, we are a research and technology transfer instititue in Germany, and some of us have recently started to work on secure software development (we have a long tradition of security analysis of systems, processes, and some software). One item on our agenda is to develop a source code auditing tool (we also have experience with building non-security-related reverse engineering tools). However, we are not really sure what type of security property of a program could be both clearly relevant in practice as well as automatically determinable from the source code (most preferably without requiring special annotations!) with an effort of (say) 6 person months of work. Buffer overflow detection in C programs is the first thing that comes to mind, but there are already various efforts in this direction (source code scanners and other things like compiler support). Another idea we have come up with is building an input validation checker similar to Perl's taint mode other languages (most probably Java, C++, or C). Do you think that taint checking would cover a noteworthy share of _pratical_ software security bugs? Or what else would you suggest instead? We are aware of tools like flawfinder, ITS4, RATS, MOPS, Splint. Thank you for your opinion, Holger Peine -- Dr. Holger Peine Fraunhofer IESE, Kaiserslautern, Germany Phone +49-6301-707-134, Fax -209 (shared) www.iese.fraunhofer.de/Staff/peine -- PGP key on request or via pgp.mit.edu