-
1
-
-
84858463487
-
-
Build-Interceptor. Website, 2007. http://freshmeat.net/ projects/build-interceptor/.
-
(2007)
Website
-
-
Build-Interceptor1
-
2
-
-
84858472533
-
-
Elsa. Website, 2007. http://www.cs.berkeley.edu/~smcpeak/ elkhound/sources/elsa/.
-
(2007)
Website
-
-
Elsa1
-
3
-
-
84858462679
-
-
Oink. Website, 2007. http://freshmeat.net/projects/oink/.
-
(2007)
Website
-
-
Oink1
-
4
-
-
0038716509
-
Checking and inferring local, non-aliasing
-
Alex Aiken, Jeffrey Foster, John Kodumal, and Tachio Terauchi. Checking and inferring local, non-aliasing. In Proc. of the Conference on Programming Language Design and Implementation, 2003.
-
(2003)
Proc. of the Conference on Programming Language Design and Implementation
-
-
Aiken, A.1
Foster, J.2
Kodumal, J.3
Terauchi, T.4
-
7
-
-
1442263220
-
Scrash: A system for generating secure crash, information
-
August
-
Pete Broadwell, Matt Harren, and Naveen Sastry. Scrash: A system for generating secure crash, information. In Proc. of the 12th USENIX Security Symposium, pages 273-284, August 2003.
-
(2003)
Proc. of the 12th USENIX Security Symposium
, pp. 273-284
-
-
Broadwell, P.1
Harren, M.2
Sastry, N.3
-
8
-
-
0033688092
-
A static analyzer for finding dynamic programming errors
-
William R. Bush, Jonathan D. Pincus, and David J. Sielaff. A static analyzer for finding dynamic programming errors. Software Practice and Experience, 30(7):775-802, 2000.
-
(2000)
Software Practice and Experience
, vol.30
, Issue.7
, pp. 775-802
-
-
Bush, W.R.1
Pincus, J.D.2
Sielaff, D.J.3
-
10
-
-
85084161775
-
FormatGuard: Automatic protection from printf format string vulnerabilities
-
Crispin Cowan, Matt Barringer, Steve Beattie, Greg Kroah-Hartman, Mike Frantzen, and Jamie Lokier. FormatGuard: Automatic protection from printf format string vulnerabilities. In Proc. of the 10th USENIX Security Symposium., pages 191-200, 2001.
-
(2001)
Proc. of the 10th USENIX Security Symposium
, pp. 191-200
-
-
Cowan, C.1
Barringer, M.2
Beattie, S.3
Kroah-Hartman, G.4
Frantzen, M.5
Lokier, J.6
-
11
-
-
36448993763
-
-
Alan DeKok. PScan: A limited problem scanner for C. Website, 2000. http://packages.debian.org/pscan.
-
Alan DeKok. PScan: A limited problem scanner for C. Website, 2000. http://packages.debian.org/pscan.
-
-
-
-
13
-
-
0036147522
-
Improving security using extensible lightweight static analysis
-
David Evans and David Larochelle. Improving security using extensible lightweight static analysis. IEEE Software, 19(1), 2002.
-
(2002)
IEEE Software
, vol.19
, Issue.1
-
-
Evans, D.1
Larochelle, D.2
-
16
-
-
33845512960
-
Flow-insensitive type qualifiers
-
November
-
Jeffrey S. Foster, Robert T. Johnson, John Kodumal, and Alex Aiken. Flow-insensitive type qualifiers. ACM Transactions on Programming Languages and Systems, pages 1035-1086, November 2006.
-
(2006)
ACM Transactions on Programming Languages and Systems
, pp. 1035-1086
-
-
Foster, J.S.1
Johnson, R.T.2
Kodumal, J.3
Aiken, A.4
-
19
-
-
84858480025
-
Type qualifiers for Java
-
Technical report, University of Maryland, August, projects/PL/jqual
-
David Greenfieldboyce and Jeffrey S. Foster. Type qualifiers for Java. Technical report, University of Maryland, August 2007. http://www.cs.umd.edu/ projects/PL/jqual/.
-
(2007)
-
-
Greenfieldboyce, D.1
Foster, J.S.2
-
20
-
-
84858475927
-
Guyer, Emery Berger, and Calvin Lin. Detecting errors with configurable whole-program dataflow analysis
-
Technical report, University of Texas at Austin
-
Samuel Guyer, Emery Berger, and Calvin Lin. Detecting errors with configurable whole-program dataflow analysis. Technical report, University of Texas at Austin, 2002. ftp://ftp.cs.utexas.edu/ pub/emery/papers/detecting- errors.pdf.
-
(2002)
-
-
Samuel1
-
21
-
-
0036039794
-
A system and language for building system-specific, static analyses
-
Seth Hallein, Benjamin Chelf, Yichen Xie, and Dawson Engler. A system and language for building system-specific, static analyses. In Proc. of the SIGPLAN 2002 Conference on Programming Language Design and Implementation (PLDI), 2002.
-
(2002)
Proc. of the SIGPLAN 2002 Conference on Programming Language Design and Implementation (PLDI)
-
-
Hallein, S.1
Chelf, B.2
Xie, Y.3
Engler, D.4
-
24
-
-
33751027156
-
Pixy: A static analysis tool for detecting web application vulnerabilities (short paper)
-
IEEE Computer Society
-
Nenad Jovanovic, Christopher Krügel, and Engin Kirda. Pixy: A static analysis tool for detecting web application vulnerabilities (short paper). In IEEE Symposium on Security and Privacy (Oakland 2006), pages 258-263. IEEE Computer Society, 2006.
-
(2006)
IEEE Symposium on Security and Privacy (Oakland 2006)
, pp. 258-263
-
-
Jovanovic, N.1
Krügel, C.2
Kirda, E.3
-
25
-
-
33745787285
-
-
PhD thesis, University of California, Berkeley
-
Ben Liblit. Cooperative Bug Isolation. PhD thesis, University of California, Berkeley, 2005.
-
(2005)
Cooperative Bug Isolation
-
-
Liblit, B.1
-
28
-
-
84871349041
-
Automatically hardening web applications using precise tainting
-
A. Nguyen-Tuong, S. Guarnieri, D. Greene, J. Shirley, and D. Evans. Automatically hardening web applications using precise tainting. In 20th IFIP International Information Security Conference, 2005.
-
(2005)
20th IFIP International Information Security Conference
-
-
Nguyen-Tuong, A.1
Guarnieri, S.2
Greene, D.3
Shirley, J.4
Evans, D.5
-
30
-
-
84858454760
-
-
Tim Robbins. Libformat, 2000. http://archives.neohapsis. com/archives/linux/lsap/2000-q3/0444.html.
-
(2000)
-
-
-
33
-
-
0012528068
-
Libsafe 2.0: Detection of format string vulnerability exploits
-
Technical report, Avaya Labs, February 2001
-
Timothy Tsai and Navjot Singh. Libsafe 2.0: Detection of format string vulnerability exploits. Technical report, Avaya Labs, February 2001. http://pubs.research.avayalabs.com/pdfs/ ALR-2001-018-whpaper.pdf.
-
-
-
Tsai, T.1
Singh, N.2
-
34
-
-
85002253400
-
ITS4: A static vulnerability scanner for C and C++ code
-
John. Viega, J. T. Bloch, Tadayoshi Kohno, and Gary McGraw. ITS4: A static vulnerability scanner for C and C++ code. ACM Transactions on Information and System Security, 5(2), 2002.
-
(2002)
ACM Transactions on Information and System Security
, vol.5
, Issue.2
-
-
John1
Viega2
Bloch, J.T.3
Kohno, T.4
McGraw, G.5
-
35
-
-
36448974988
-
-
Common Vulnerabilities and Exposures. Format string vulnerabilities. Website, 2007. http://www.cve.mitre.org/cgi-bin/ cvekey.cgi?keyword= format+string.
-
Common Vulnerabilities and Exposures. Format string vulnerabilities. Website, 2007. http://www.cve.mitre.org/cgi-bin/ cvekey.cgi?keyword= format+string.
-
-
-
-
38
-
-
14844302134
-
MECA: An extensible, expressive system and language for statically checking security properties
-
Junfeng Yang, Ted Kremenek, Yichen Xie, and Dawson Engler. MECA: an extensible, expressive system and language for statically checking security properties. In Proc. of the 10th ACM Conference on Computer and Communications Security (CCS), 2003.
-
(2003)
Proc. of the 10th ACM Conference on Computer and Communications Security (CCS)
-
-
Yang, J.1
Kremenek, T.2
Xie, Y.3
Engler, D.4
|