...
首页> 外文期刊>Programming and Computer Software >Directed Dynamic Symbolic Execution for Static Analysis Warnings Confirmation
【24h】

Directed Dynamic Symbolic Execution for Static Analysis Warnings Confirmation

机译:用于静态分析警告确认的定向动态符号执行

获取原文
获取原文并翻译 | 示例
           

摘要

Currently, there is no doubt among experts in the field of program certification and quality assurance that automated program analysis methods should be used to find bugs that lead to program security vulnerabilities. The national standard for the secure software development requires the use of source code static analysis tools as one of the measures of software quality assurance at the development stage and the application of dynamic analysis and fuzz-testing of the source code at the qualification testing stage. Fundamental limitations of automated program analysis and testing methods make it impossible to carry out simultaneously exhaustive and precise analysis of programs for errors. Thereof, researches are nowadays carried out aimed at reducing the effect of fundamental limitations on the quality and productivity of automated software error detection methods. This paper discusses an approach that combines methods of source code static analysis and dynamic symbolic execution in order to increase the program error detection efficiency.
机译:当前,毫无疑问,程序认证和质量保证领域的专家应该使用自动程序分析方法来查找导致程序安全漏洞的错误。安全软件开发的国家标准要求在开发阶段使用源代码静态分析工具作为软件质量保证的措施之一,并在资格测试阶段对源代码进行动态分析和模糊测试。自动化程序分析和测试方法的根本局限性使得不可能同时对程序进行详尽而精确的错误分析。因此,当今进行的研究旨在减少基本限制对自动软件错误检测方法的质量和生产率的影响。本文讨论了一种结合源代码静态分析和动态符号执行方法以提高程序错误检测效率的方法。

著录项

  • 来源
    《Programming and Computer Software》 |2018年第5期|316-323|共8页
  • 作者

    Gerasimov A. Yu;

  • 作者单位

    Russian Acad Sci, VP Ivannikov Inst Syst Programming, Ul Solzhenitsyna 25, Moscow 109004, Russia;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号