Other third-party tools, proprietary or open source, which can do
sophisticated static code analysis include klocwork[31],
fortify[32], coverity[33], Enterprise Architect[34], Findbugs[35],
PMD[36], etc. All these tools can statically analyze code written
in one or more of the languages like C/C++, java, C#, Delphi, VB
etc. NIST annually holds a Static Analysis Tool Exposition
(SATE) [27] to advance research in static analysis tools to find
bugs related to security problems. But these tools or solutions
analyze code structures and dependencies to find security
vulnerabilities and programming bugs like resource leaks,
unreferenced variables etc. and report the defects in details. They
mainly work in the context of a specific programming language,
ignoring database interactions.
Other third-party tools, proprietary or open source, which can dosophisticated static code analysis include klocwork[31],fortify[32], coverity[33], Enterprise Architect[34], Findbugs[35],PMD[36], etc. All these tools can statically analyze code writtenin one or more of the languages like C/C++, java, C#, Delphi, VBetc. NIST annually holds a Static Analysis Tool Exposition(SATE) [27] to advance research in static analysis tools to findbugs related to security problems. But these tools or solutionsanalyze code structures and dependencies to find securityvulnerabilities and programming bugs like resource leaks,unreferenced variables etc. and report the defects in details. Theymainly work in the context of a specific programming language,ignoring database interactions.
การแปล กรุณารอสักครู่..

Other third-party tools, proprietary or open source, which can do
sophisticated static code analysis include klocwork[31],
fortify[32], coverity[33], Enterprise Architect[34], Findbugs[35],
PMD[36], etc. All these tools can statically analyze code written
in one or more of the languages like C/C++, java, C#, Delphi, VB
etc. NIST annually holds a Static Analysis Tool Exposition
(SATE) [27] to advance research in static analysis tools to find
bugs related to security problems. But these tools or solutions
analyze code structures and dependencies to find security
vulnerabilities and programming bugs like resource leaks,
unreferenced variables etc. and report the defects in details. They
mainly work in the context of a specific programming language,
ignoring database interactions.
การแปล กรุณารอสักครู่..
