• DocumentCode
    1358159
  • Title

    Fix it, don´t nix it [IT security]

  • Author

    Tapp, C.

  • Volume
    4
  • Issue
    18
  • fYear
    2009
  • Firstpage
    58
  • Lastpage
    59
  • Abstract
    The article discusses the security in C programming language. Critics claim that the decades-old C programming language is inherently insecure. The author disagrees. Programmers just have to use security tools to fix software vulnerabilities.Research in recent years has identified the root cause of many of the vulnerabilities typically found in C/C++ code. Coding standards such as the CERT C Secure Coding Standard help programmers avoid the associated pitfalls. However, without automated tools to check for non-compliance, it is, arguably, more or less impossible for a programmer to deliver fault-free code. Software analysis tools for static code analysis are available to enforce compliance with the guidelines recommended by these established coding standards. They can perform in-depth, systemwide analysis of the code, and can utilise formal methods to ensure that system security is not compromised. Software tools enforce compliance with the guidelines recommended by established coding standards.
  • Keywords
    C++ language; codes; formal specification; security of data; C programming language; C/C++ code; CERT C secure coding standard; formal methods; software analysis tools; static code analysis; system security;
  • fLanguage
    English
  • Journal_Title
    Engineering & Technology
  • Publisher
    iet
  • ISSN
    1750-9637
  • Type

    jour

  • Filename
    5353788