@article{ART002210304},
author={Han, Kyung sook and Damho Lee and Changwoo Pyo},
title={Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2017},
volume={22},
number={3},
pages={81-88},
doi={10.9708/jksci.2017.22.03.081}
TY - JOUR
AU - Han, Kyung sook
AU - Damho Lee
AU - Changwoo Pyo
TI - Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs
JO - Journal of The Korea Society of Computer and Information
PY - 2017
VL - 22
IS - 3
PB - The Korean Society Of Computer And Information
SP - 81
EP - 88
SN - 1598-849X
AB - In this paper, we classified the weaknesses of C/C++ programs listed in CWE based on the diagnostic information produced at each stage of program compilation. Our classification identifies which stages should be responsible for analyzing the weaknesses. We also present algorithmic frameworks for detecting typical weaknesses belonging to the classes to demonstrate validness of our scheme. For the weaknesses that cannot be analyzed by using the diagnostic information, we separated them as a group that are often detectable by the analyses that simulate program execution, for instance, symbolic execution and abstract interpretation. We expect that classification of weaknesses, and diagnostic information accordingly, would contribute to systematic development of static analyzers that minimizes false positives and negatives.
KW - Security;Weakness;Static Analysis;Diagnostic Information;Analysis Method
DO - 10.9708/jksci.2017.22.03.081
ER -
Han, Kyung sook, Damho Lee and Changwoo Pyo. (2017). Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs. Journal of The Korea Society of Computer and Information, 22(3), 81-88.
Han, Kyung sook, Damho Lee and Changwoo Pyo. 2017, "Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs", Journal of The Korea Society of Computer and Information, vol.22, no.3 pp.81-88. Available from: doi:10.9708/jksci.2017.22.03.081
Han, Kyung sook, Damho Lee, Changwoo Pyo "Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs" Journal of The Korea Society of Computer and Information 22.3 pp.81-88 (2017) : 81.
Han, Kyung sook, Damho Lee, Changwoo Pyo. Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs. 2017; 22(3), 81-88. Available from: doi:10.9708/jksci.2017.22.03.081
Han, Kyung sook, Damho Lee and Changwoo Pyo. "Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs" Journal of The Korea Society of Computer and Information 22, no.3 (2017) : 81-88.doi: 10.9708/jksci.2017.22.03.081
Han, Kyung sook; Damho Lee; Changwoo Pyo. Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs. Journal of The Korea Society of Computer and Information, 22(3), 81-88. doi: 10.9708/jksci.2017.22.03.081
Han, Kyung sook; Damho Lee; Changwoo Pyo. Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs. Journal of The Korea Society of Computer and Information. 2017; 22(3) 81-88. doi: 10.9708/jksci.2017.22.03.081
Han, Kyung sook, Damho Lee, Changwoo Pyo. Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs. 2017; 22(3), 81-88. Available from: doi:10.9708/jksci.2017.22.03.081
Han, Kyung sook, Damho Lee and Changwoo Pyo. "Classification of Diagnostic Information and Analysis Methods for Weaknesses in C/C++ Programs" Journal of The Korea Society of Computer and Information 22, no.3 (2017) : 81-88.doi: 10.9708/jksci.2017.22.03.081