메뉴 건너뛰기




Volumn , Issue , 2007, Pages 18-

Toward the use of automated static analysis alerts for early identification of vulnerability- and attack-prone components

Author keywords

[No Author keywords available]

Indexed keywords

AUTOMATION; COMPUTER CRIME; IDENTIFICATION (CONTROL SYSTEMS); RISK ANALYSIS; SOFTWARE DESIGN; STATIC ANALYSIS;

EID: 35348918737     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1109/ICIMP.2007.46     Document Type: Conference Paper
Times cited : (19)

References (43)
  • 3
    • 0003687951 scopus 로고    scopus 로고
    • Investigating Quality Factors in Object-Oriented Designs: An Industrial Case Study
    • L. C. Briand, J. Wust, and H. Lounis, "Investigating Quality Factors in Object-Oriented Designs: An Industrial Case Study," ISERN-98-29, 1998.
    • (1998) ISERN-98-29
    • Briand, L.C.1    Wust, J.2    Lounis, H.3
  • 4
    • 33746592989 scopus 로고    scopus 로고
    • Putting the Tools to Work: How to Succeed with Source Code Analysis
    • P. Chandra, B. Chess, and J. Steven, "Putting the Tools to Work: How to Succeed with Source Code Analysis," in IEEE Security & Privacy, vol. 4, 2006, pp. 80-83.
    • (2006) IEEE Security & Privacy , vol.4 , pp. 80-83
    • Chandra, P.1    Chess, B.2    Steven, J.3
  • 5
    • 0036079901 scopus 로고    scopus 로고
    • Improving Computer Security using Extended Static Checking
    • Berkeley, CA
    • B. Chess, "Improving Computer Security using Extended Static Checking," in IEEE Symposium on Security and Privacy, Berkeley, CA, 2002, pp. 160-173.
    • (2002) IEEE Symposium on Security and Privacy , pp. 160-173
    • Chess, B.1
  • 6
    • 10944267118 scopus 로고    scopus 로고
    • Static Analysis for Security
    • B. Chess and G. McGraw, "Static Analysis for Security," in IEEE Security and Privacy, vol. 2, 2004, pp. 76-79.
    • (2004) IEEE Security and Privacy , vol.2 , pp. 76-79
    • Chess, B.1    McGraw, G.2
  • 8
    • 3543055843 scopus 로고    scopus 로고
    • Early Performance Testing of Distributed Software Applications
    • Redwood Shores, California
    • G. Denaro, A. Polini, and W. Emmerich, "Early Performance Testing of Distributed Software Applications," in Workshop on Software and Performance, Redwood Shores, California, 2004, pp. 94-103
    • (2004) Workshop on Software and Performance , pp. 94-103
    • Denaro, G.1    Polini, A.2    Emmerich, W.3
  • 10
    • 0035394038 scopus 로고    scopus 로고
    • The Confounding Effect of Class Size on the Validity of Object-Oriented Metrics
    • July
    • K. El Emam, S. Benlarbi, N. Goel, and S. N. Rai, "The Confounding Effect of Class Size on the Validity of Object-Oriented Metrics," IEEE Trans. Software Eng., vol. 27, pp. 630-650 July 2001.
    • (2001) IEEE Trans. Software Eng , vol.27 , pp. 630-650
    • El Emam, K.1    Benlarbi, S.2    Goel, N.3    Rai, S.N.4
  • 11
    • 30344485154 scopus 로고    scopus 로고
    • Empirical Validation of Object-Oriented Metrics on Open Source Software for Fault Prediction
    • Oct
    • T. Gyimothy, R. Ference, and L. Siket, "Empirical Validation of Object-Oriented Metrics on Open Source Software for Fault Prediction," IEEE Trans. Software Eng., vol. 31, pp. 897-910, Oct. 2005.
    • (2005) IEEE Trans. Software Eng , vol.31 , pp. 897-910
    • Gyimothy, T.1    Ference, R.2    Siket, L.3
  • 18
    • 0036891333 scopus 로고    scopus 로고
    • Using Regression Trees to Classify Fault-Prone Software Modules
    • December
    • T. M. Khoshgoftaar, E. B. Allen, and J. Deng, "Using Regression Trees to Classify Fault-Prone Software Modules," IEEE Transactions on Reliability, vol. 51, pp. 455-562, December, 2002 2002.
    • (2002) IEEE Transactions on Reliability , vol.51 , pp. 455-562
    • Khoshgoftaar, T.M.1    Allen, E.B.2    Deng, J.3
  • 20
    • 0031192278 scopus 로고    scopus 로고
    • Applications of Neural Networks to Software Quality Modeling of a Very Large Telecommunications System
    • T. M. Khoshgoftaar, E. B. Allen, J. P. Hudepohl, and S. J. Aud, "Applications of Neural Networks to Software Quality Modeling of a Very Large Telecommunications System," Trans. Neural Networks, vol. 8, pp. 902-909, 1997.
    • (1997) Trans. Neural Networks , vol.8 , pp. 902-909
    • Khoshgoftaar, T.M.1    Allen, E.B.2    Hudepohl, J.P.3    Aud, S.J.4
  • 25
    • 35348861419 scopus 로고    scopus 로고
    • I. Krsul, Software Vulnerability Analysis, in Computer Science, PhD West Lafayette: Purdue University, 1998.
    • I. Krsul, "Software Vulnerability Analysis," in Computer Science, vol. PhD West Lafayette: Purdue University, 1998.
  • 27
    • 33845782503 scopus 로고    scopus 로고
    • Data Mining Static Code Attributes to Learn Defect Predictors
    • T. Menzies, J. Greenwald, and A. Frank, "Data Mining Static Code Attributes to Learn Defect Predictors," IEEE Trans. Software Eng., vol. 33, pp. 2-13, 2007.
    • (2007) IEEE Trans. Software Eng , vol.33 , pp. 2-13
    • Menzies, T.1    Greenwald, J.2    Frank, A.3
  • 29
    • 32344432493 scopus 로고    scopus 로고
    • A Software Testing and Reliability Early Warning (STREW) Metric Suite
    • Raleigh, NC: North Carolina State University
    • N. Nagappan, "A Software Testing and Reliability Early Warning (STREW) Metric Suite," in Computer Science Raleigh, NC: North Carolina State University, 2005.
    • (2005) Computer Science
    • Nagappan, N.1
  • 30
    • 33244495065 scopus 로고    scopus 로고
    • Static Analysis Tools as Early Indicators of Pre-release Defect Density
    • St. Louis, MO
    • N. Nagappan and T. Ball, "Static Analysis Tools as Early Indicators of Pre-release Defect Density," in International Conference on Software Engineering, St. Louis, MO, 2005, pp. 580-586.
    • (2005) International Conference on Software Engineering , pp. 580-586
    • Nagappan, N.1    Ball, T.2
  • 31
    • 34547700305 scopus 로고    scopus 로고
    • Using Historical In-Process and Product Metrics for Early Estimation of Software Failures
    • Raleigh, NC
    • N. Nagappan, T. Ball, and B. Murphy, "Using Historical In-Process and Product Metrics for Early Estimation of Software Failures," in International Symposium on Software Reliability Engineering, Raleigh, NC, 2006, pp. 62-74.
    • (2006) International Symposium on Software Reliability Engineering , pp. 62-74
    • Nagappan, N.1    Ball, T.2    Murphy, B.3
  • 33
    • 33750961045 scopus 로고    scopus 로고
    • N. Nagappan, L. Williams, J. Osborne, M. Vouk, and P. Abrahamsson, Providing Test Quality Feedback Using Static Source Code and Automatic Test Suite Metrics, in Chicago, IL, International Symposium on Software Reliability Engineering (ISSRE) 2005, 2005, pp. 85-94.
    • N. Nagappan, L. Williams, J. Osborne, M. Vouk, and P. Abrahamsson, " Providing Test Quality Feedback Using Static Source Code and Automatic Test Suite Metrics," in Chicago, IL, International Symposium on Software Reliability Engineering (ISSRE) 2005, 2005, pp. 85-94.
  • 39
    • 0038300307 scopus 로고    scopus 로고
    • Empirical Analysis of CK Metrics for Object-Oriented Design Complexity: Implications for Software Defects
    • April
    • R. Subramanyam and M. S. Krishnan, "Empirical Analysis of CK Metrics for Object-Oriented Design Complexity: Implications for Software Defects," IEEE Transactions on Software Engineering, vol. 29, pp. 297-310, April 2003.
    • (2003) IEEE Transactions on Software Engineering , vol.29 , pp. 297-310
    • Subramanyam, R.1    Krishnan, M.S.2
  • 40
    • 0029707041 scopus 로고    scopus 로고
    • Defining an Adaptive Software Security Metric from a Dynamic Software Failure Tolerance Measure
    • Gaithersburg, MD
    • J. Voas, A. Ghosh, G. McGraw, F. Charron, and K. Miller, "Defining an Adaptive Software Security Metric from a Dynamic Software Failure Tolerance Measure," in COMPASS '96, Gaithersburg, MD, 1996, pp. 250-263.
    • (1996) COMPASS '96 , pp. 250-263
    • Voas, J.1    Ghosh, A.2    McGraw, G.3    Charron, F.4    Miller, K.5
  • 43
    • 33947174112 scopus 로고    scopus 로고
    • Empirical Analysis of Object-Oriented Design Metrics for Predicting High and Low Severity Faults
    • October
    • Y. Zhou and L. Hareton, "Empirical Analysis of Object-Oriented Design Metrics for Predicting High and Low Severity Faults," IEEE Transactions on Software Engineering, vol. 32, pp. 771-789, October 2006.
    • (2006) IEEE Transactions on Software Engineering , vol.32 , pp. 771-789
    • Zhou, Y.1    Hareton, L.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.