OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: code auditing tools
From: Crispin Cowan (crispinWIREX.COM)
Date: Tue Nov 21 2000 - 13:13:21 CST


Oliver Friedrichs wrote:

> What do people think of automated source code review? Does anyone know of
> any other programs to assist in auditing source code? The only one I know
> of is ITS4:
>
> ITS4
> http://www.rstcorp.com/its4

Auditing tools that have not yet been mentioned:

   * David Wagner's static analysis tool for scanning for buffer overflow
     vulnerabilities. There is no one home page for it; it is the paper
     entitled "A First Step Towards Automated Detection of Buffer Overrun
     Vulnerabilities" on this page http://www.cs.berkeley.edu/~daw/papers/
   * Matt Bishop's file system race condition analyzer. Again no hope page,
     but it is the first 1996 paper on this page
     http://olympus.cs.ucdavis.edu/~bishop/scriv/index.html
   * LCLint http://lclint.cs.virginia.edu/

And no gratuitous plugs for Immunix tools, 'cause we don't do static analysis
:-)

Crispin

--
Crispin Cowan, Ph.D.
Chief Research Scientist, WireX Communications, Inc. http://wirex.com
Free Hardened Linux Distribution:                    http://immunix.org