master thesis
Evaluating Static Source Code Analysis Tools
Hofer, Thomas
2010
This thesis presents the results of an evaluation of source code analyzers. Such tools constitute an inexpensive, efficient and fast way of removing the most common vulnerabilities in a software project, even though not all security flaws can be detected. This evaluation was conducted at CERN, the European Organization for Nuclear Research, in the intent of providing its programmers with a list of dedicated software verification/static source code analysis tools. Particular focus of these tools should be on efficiently finding security flaws. The evaluation covered close to thirty different tools for the major programming languages.
Type
master thesis
Author(s)
Hofer, Thomas
Advisors
Oechslin, Philippe
•
Lueders, Stefan
•
Lopienski, Sebastian
Date Issued
2010
Note
This master thesis has been awarded the Kudelski Prize.
Written at
OTHER
EPFL units
Available on Infoscience
October 11, 2010
Use this identifier to reference this record