Presentation is loading. Please wait.

Presentation is loading. Please wait.

Tools for Code Review Static Analysis Handles unfinished code

Similar presentations


Presentation on theme: "Tools for Code Review Static Analysis Handles unfinished code"— Presentation transcript:

1 Tools for Code Review Static Analysis Handles unfinished code
Can find backdoors Potentially complete Dynamic Analysis Run code Code not needed Has few(er) assumptions Covers end-to-end or system tests

2 Static Analysis tools Open Source Static Analysis tools
Cppcheck, Rough Auditing Tool for Security (RATS), Flawfinder, Evaluate, based on Efficiency Correctness Speed Understandability of the results

3 Results and Major Contributions
Outcome of students’ evaluation: Flawfinder is most Efficient Cppcheck is most Accurate of all RATS is Fastest and its Results understandability is good

4 Sample Vulnerabilities
SAMATE Reference Dataset (SRD) Search for common vulnerabilities Experiment with tools


Download ppt "Tools for Code Review Static Analysis Handles unfinished code"

Similar presentations


Ads by Google