A Comparison of Static Analysis Technology for Intrusion Prevention

WU Chunmei,XIA Nai,MAO Bing
DOI: https://doi.org/10.3969/j.issn.1000-3428.2006.03.063
2006-01-01
Abstract:A testbed which includes the common vulnerabilities is built.The paper compares three typical and publicly available tools by applying them to the testbed individually for sake of preventing intrusion.The result reveals that the tools building on finding vulnerable library functions have low false negatives rates but high false positives rates,the constrained based tools have low false positives rates but high false negatives rates,and the module checkers have high true positives rates when finding attacks against given security rules,but have high false negatives rates when finding many kinds of vulnerabilities.
What problem does this paper attempt to address?