Verification of CERT Secure Coding Rules: Case Studies

  • Authors:
  • Syrine Tlili;Xiaochun Yang;Rachid Hadjidj;Mourad Debbabi

  • Affiliations:
  • Computer Security Laboratory, Concordia Institute for Information Systems Engineering, Concordia University, Montreal, Canada;Computer Security Laboratory, Concordia Institute for Information Systems Engineering, Concordia University, Montreal, Canada;Computer Security Laboratory, Concordia Institute for Information Systems Engineering, Concordia University, Montreal, Canada;Computer Security Laboratory, Concordia Institute for Information Systems Engineering, Concordia University, Montreal, Canada

  • Venue:
  • OTM '09 Proceedings of the Confederated International Conferences, CoopIS, DOA, IS, and ODBASE 2009 on On the Move to Meaningful Internet Systems: Part II
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Growing security requirements for systems and applications have raised the stakes on software security verification techniques. Recently, model-checking is settling in the arena of software verification. It is effective in verifying high-level security properties related to software functionalities. In this paper, we present the experiments conducted with our security verification framework based on model-checking. We embedded a wide range of the CERT secure coding rules into our framework. Then, we verified real software packages against these rules for purpose of demonstrating the capability and the efficiency of our tool in detecting real errors.