Scalable Security Verification of Software at Compile Time

Autor: José M. Fernandez, Abdelfettah Belghith, Syrine Tlili, Bilel Dridi, Soufien Hidouri
Rok vydání: 2014
Předmět:
Zdroj: SCAM
Popis: Automated verification tools are required to detect coding errors that may lead to severe software vulnerabilities. However, the usage of these tools is still not well integrated into software development life cycle. In this paper, we present our approach that brings the software compilation process and security verification to a meeting point where both can be applied simultaneously in a user-friendly manner. Our security verification engine is implemented as a new GCC pass that can be enabled via flag-fsecurity-check=checks.xml where the input XML file contains a set of user-defined security checks. The verification operates on the GIMPLE intermediate representation of source code that is language and platform independent. The conducted experiments demonstrate the scalability, efficiency and performance of our engine used to verify large scale software, especially the entire Linux kernel source code.
Databáze: OpenAIRE