Is a False Positive really False Positive?

Hong Jun Choi,Hyuk Lee,Jin-Young Choi

2021 23rd International Conference on Advanced Communication Technology (ICACT)(2021)

引用 1|浏览0
暂无评分
摘要
As the number of devices with software increases, software reliability and security has become more critical. To improve reliability and security, developers and test engineers use static analysis tools to find defects early in the development process. However, it takes a lot of time and effort to determine whether alarms from performing static analysis are true or false positive. In this paper, we argue that all integer overflow generated by static analysis tools are weaknesses and should eventually be corrected. To show that our argument is reasonable, we explain static analysis results for binary search program code and CWE:190 example code in terms of reliability and security. It is unnecessary to identify whether the integer overflow generated by static analysis tools is true or false positive.
更多
查看译文
关键词
Software Reliability,Software Security,Static Analysis,Integer Overflow,True Positive,False Positive
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要