Thesis/Dissertation: Bc. David Formánek: Detection of security bugs using static code analysis
Master's thesis
Detection of security bugs using static code analysis
Detekce bezpečnostních chyb pomocí statické analýzy kódu
Abstract
Práce se zabývá automatickou statickou analýzou kódu a jejím využitím pro detekci třídy bezpečnostních zranitelností nazývaných jako injekce. Kromě nezbytné teorie je především popsána vlastní implementace nového mechanismu, který pomocí tzv. taint analýzy umožňuje tyto chyby spolehlivě detekovat v Java aplikacích. Tento mechanismus byl integrován do rozšíření FindSecurityBugs pro volně dostupný nástroj …more
Abstract
The thesis deals with static code analysis and its usage for detection of a class of security bugs called injections. Besides the needful theory, we describe own implementation of a new mechanism that allows reliable detection of those bugs in Java applications by utilizing so-called taint analysis. This mechanism has been integrated into FindSecurityBugs - extension for the open-source tool called …more
Thesis description
31/5/2016 09:22, RNDr. Andrij Stecko, Ph.D.
- Entered/Edited 28/6/2016 13:09, Helena Kryštofová
- Record made 29/3/2016 15:19, Jana Zemanová, UČO 9619
- Accessible from: 30/5/2016 10:24, Helena Kryštofová
- Thesis/dissertation received 30/5/2016 10:24, Helena Kryštofová
Attachments
latex.zip
FindSecurityBugs-source.zip
findbugs.zip
Theses on a related topic
List of theses with an identical keyword.
-
The static and dynamic analysis source code tools with focus on security bug finding
Mgr. David Formánek -
Finding SQL Injection Vulnerabilities in a C# Source Code
Mgr. Michal Klein, UČO 514072 -
Static pointer analysis for the C language
Mgr. Michal Strehovský, UČO 139566 -
Determining malware similarities
Mgr. Ondřej Fujtík -
Automatic error detection tool for the C language
Mgr. Jan Šťastný, UČO 173461 -
Enhancing DiffKemp to Support Generic Projects
Mgr. Tomáš Glozar, UČO 492787 -
Security Analysis of Oracle Vulnerabilities in Ethereum Smart Contracts
Bc. Ondřej Tatýrek -
C++ support for Stanse
Mgr. Martin Vejnár, UČO 172430




