Clang and Coccinelle: synergising program analysis tools for CERT C Secure Coding Standard certification

Mads Christian Olesen, René Rydhof Hansen, Julia Lawall, Nicolas Jean-Michel Palix

1 Citationer (Scopus)
11 Downloads (Pure)

Abstract

Writing correct C programs is well-known to be hard, not least due
to the many interesting language features intrinsic to C. Writing
secure C programs is even harder and, at times, seemingly
impossible. To improve on this situation the US CERT has developed
and published a set of coding standards, the ``CERT C Secure Coding
Standard'', that enumerates a number of rules and recommendations
with the aim of making C programs (more) secure. Automated tool
support is essential for certifying that a given system is in
compliance with the rules and/or recommendations of the standards.

In this paper we report on work-in-progress with integrating two
state of the art analysis tools, Clang and Coccinelle, into a
combined tool perfectly suited for analysing and certifying C
programs according to, e.g., the CERT C Secure Coding standard or
the MISRA (the Motor Industry Software Reliability Assocation) C
standard. We further argue that such a tool must be highly adaptable
and customisable to individual software projects as well as to the
certification rules required by a given standard.

Clang is the C frontend for the LLVM compiler/virtual machine
project which includes a comprehensive set of static analyses and
code code checkers. Coccinelle is a program transformation tool and
bug-finder developed originally for the Linux kernel but has been
successfully used to find bugs in other Open Source projects such as
WINE and OpenSSL.
OriginalsprogEngelsk
TitelProceedings of the Fourth International Workshop on Foundations and Tecniques for Open Source Software Certification (OpenCert 2010)
RedaktørerLuis S. Barbosa, Antonio Cerone, Siraj A. Shaikh
Antal sider18
Publikationsdatosep. 2010
DOI
StatusUdgivet - sep. 2010
Begivenhed4th International Workshop on Foundations and Techniques for Open Source Software Certification - Pisa, Italien
Varighed: 17 sep. 201018 sep. 2010
Konferencens nummer: 4

Konference

Konference4th International Workshop on Foundations and Techniques for Open Source Software Certification
Nummer4
Land/OmrådeItalien
ByPisa
Periode17/09/201018/09/2010
NavnElectronic Communications of the EASST
Vol/bind33
ISSN1863-2122

Fingeraftryk

Dyk ned i forskningsemnerne om 'Clang and Coccinelle: synergising program analysis tools for CERT C Secure Coding Standard certification'. Sammen danner de et unikt fingeraftryk.

Citationsformater