Title :
Vulnerability Detection Systems: Think Cyborg, Not Robot
Author_Institution :
Immunity Inc.
Abstract :
This paper discussed why academic research has failed to create effective vulnerability detection software and offer some suggestions on how we can reap practical benefits from future research. The reasons for this failure also help explain why this software can´t be completely automatic but must in corporate human knowledge and capabilities to be effective.
Keywords :
security of data; security bugs; symbolic execution system; vulnerability detection software; Browsers; Computer bugs; Computer security; Detection algorithms; Prototypes; Software; security; security and privacy; software engineering; software security; static analysis; symbolic execution;
Journal_Title :
Security & Privacy, IEEE
DOI :
10.1109/MSP.2011.70