发明授权
- 专利标题: After-the-fact configuration of static analysis tools able to reduce user burden
- 专利标题(中): 静态分析工具的事后配置能够减轻用户负担
-
申请号: US14024761申请日: 2013-09-12
-
公开(公告)号: US09223984B2公开(公告)日: 2015-12-29
- 发明人: Salvatore A. Guarnieri , Marco Pistoia , Omer Tripp
- 申请人: International Business Machines Corporation
- 申请人地址: KY Grand Cayman
- 专利权人: GlobalFoundries Inc.
- 当前专利权人: GlobalFoundries Inc.
- 当前专利权人地址: KY Grand Cayman
- 代理机构: Harrington & Smith
- 主分类号: G06F11/00
- IPC分类号: G06F11/00 ; G06F21/57
摘要:
A method includes mapping, based on a first mapping from possible security findings to possible configuration-related sources of imprecision, actual security findings from a static analysis of a program to corresponding configuration-related sources of imprecision, the mapping of the actual security findings creating a second mapping. A user is requested to configure selected ones of the configuration-related sources of imprecision from the second mapping. Responsive to a user updating configuration corresponding to the selected ones of the configuration-related sources of imprecision, security analysis results are updated for the static analysis of the program at least by determining whether one or more security findings from the security analysis results are no longer considered to be vulnerable based on the updated configuration by the user. The updated security analysis results are output. Apparatus and program products are also disclosed.
公开/授权文献
信息查询