|
|
|
|
ÄÄÆÄÀÏ ºôµå °úÁ¤ÀÌ ¾ø´Â Á¤Àû ºÐ¼® (Àüü/ºÎºÐ ÄÚµå ºÐ¼®/Á¡°Ë)
(no False Positive) Àüü ÇÁ·Î±×·¥¿¡¼ ÇÔ¼ö ³»/°£ ¿Ã¹Ù¸¥ °æ·Î È帧À¸·Î ¼Ò½º ÄÚµå Á¡°Ë
- Inter-procedural Path Analysis
(no Rule Option) °æ·Î È帧 ±â¹Ý ÄÚµå ¹®¸ÆÀÇ ºÐ¼® ¹× Ãß·ÐÀ¸·Î ±ÔÄ¢ ¿É¼Ç ¾øÀ½
- Path-Sensitive Analysis, Context-Sensitive Analysis
(Rule Design) "One Guide to One Rule"ÀÇ ±ÔÄ¢ ¼³°è (Áߺ¹ ±ÔÄ¢/Á¡°Ë ¿¹¹æ)
- ±ÔÄ¢ À̸§: MISRA, CWEÀÇ Ç¥ÁØ À̸§ »ç¿ë
Áö¿ø ¾ð¾î
(Procedural Language) C
(OO Language) C++, C#, Java
(Web Language) JavaScript, JSP, Flex
(Big Data Language) Python, R
(Mobile Language) iOS(Objective-C, Swift), Android(Android-Java, Kotlin)
(SAP Language) ABAP
±¹³»¿Ü Á¦Ç° ÀÎÁõ
ISO 26262, IEC 61508, EN 50128, ISO 9001 ÀÎÁõ
CWE Compatibility (º¸¾È ÀûÇÕ¼º ÀÎÁõ)
GS(1µî±Þ), NEP(½ÅÁ¦Ç° ÀÎÁõ¼), ¿ì¼öÁ¦Ç°ÁöÁ¤Áõ¼
MISRA C, MISRA C++ Copyright License Çù¾à (MIRA LIMITED)
ABAP ±¹³»¿Ü ƯÇã µî·Ï: Çѱ¹, ¹Ì±¹, È£ÁÖ, ÀϺ», Áß±¹
ÄÚµù Ç¥ÁØ °¡À̵å Á¡°Ë
»ê¾÷ ÄÚµù °¡À̵å
- (ISO 26262) MISRA C, MISRA C++, AUTOSAR C++
- (DO 178B) JPL C & Java, BSSC Java, JSF++
- (IEC 62304) HealthCare C++, (ISO 61508/62279) Railway C
- (Oracle) Java Code Conventions, (Microsoft) C# Code Conventions
Run-time °¡À̵å
- CWE-658(for C), CWE-659(for C++), CWE-660(for Java)
º¸¾È Ãë¾àÁ¡ °¡À̵å
- CWE(v 4.17), OWASP(2021), CERT(C, C++, Java)
- Çà¾ÈºÎ ¼ÒÇÁÆ®¿þ¾î °³¹ßº¸¾È °¡À̵å(2021): C, C++, Java
- Çà¾ÈºÎ ¸ð¹ÙÀÏ º¸¾È Ãë¾àÁ¡ Á¡°Ë °¡À̵å(2021): iOS, Android
- ±ÝÀ¶È¸»ç ITºÎ¹® Ãë¾àÁ¡: C, C++, Java, iOS, Android
- ÀüÀÚ±ÝÀ¶°¨µ¶±ÔÁ¤/±¹Á¤¿ø Ãë¾àÁ¡: C, C++, Java
- SAP ABAP Backdoor
ÄÚµå ǰÁú ÃøÁ¤/Æò°¡ °¡À̵å
- MISRA Software Metrics, HIS Source Code Metrics
¹«±âü°è SW ½Å·Ú¼º ½ÃÇè ¿ä±¸»çÇ× Áö¿ø
(C, C++, C#, Java Á¤Àû ½ÃÇè) ÄÚµù±ÔÄ¢, ¼ÒÇÁÆ®¿þ¾î Ãë¾àÁ¡, º¸¾È¾àÁ¡, ¼Ò½ºÄÚµå ¸ÞÆ®¸¯
(C, C++, C#, Java º¸¾È¼º ½ÃÇè) Çà¾ÈºÎ °³¹ß º¸¾È °¡À̵å
(C, C++, C#, Java µ¿Àû ½ÃÇè) ÄÚµå ½ÇÇà·ü µî
ÀÚµ¿Â÷ ¾ÈÀü¼º ¿ä±¸»çÇ× Áö¿ø
(C, C++, Java Á¤Àû °ËÁõ) MISRA-C/C++, Run-Time Error, Code Metrics
(C, C++, Java º¸¾È °ËÁõ) Â÷·®¿ë ÀÓº£µðµå º¸¾È ÄÚµù °¡À̵å(CERT-C, CWE)
(C, C++, Java, C# ´ÜÀ§/ÅëÇÕ °ËÁõ) ÄÚµå ½ÇÇàÀ², °áÇÔ ÁÖÀÔ Å×½ºÆÃ
|
|
Á¤ÀûºÐ¼®µµ±¸ - C, C++, C# »ê¾÷ Ç¥ÁØ Áö¿ø
C, C++, C# Á¤ÀûºÐ¼®µµ±¸´Â Àüü ÇÁ·Î±×·¥ ³»ÀÇ ÇÏÀ§ ÇÁ·Î±×·¥°ú ÇÔ¼öÀÇ ¿Ã¹Ù¸¥ ½ÇÇà ¼ø¼¿¡ µû¶ó µ¥ÀÌÅÍ È帧 ºÐ¼®(data-flow analysis)À» ÅëÇØ »ý¼ºµÈ °¢ °æ·Î¸¦ ±â¹ÝÀ¸·Î ÄÚµåÀÇ ÇöÀç »óŸ¦ ºÐ¼®ÇÏ¿© ÄÚµåÀÇ °áÇÔÀ̳ª Ãë¾àÁ¡À» Á¡°ËÇÏ´Â µµ±¸ÀÌ´Ù.
|
|
|
Á¤ÀûºÐ¼®µµ±¸ - Java »ê¾÷ Ç¥ÁØ Áö¿ø
Java(JSP) Á¤ÀûºÐ¼®µµ±¸´Â Àüü ÇÁ·Î±×·¥ ³»ÀÇ ÇÏÀ§ ÇÁ·Î±×·¥°ú ÇÔ¼öÀÇ ¿Ã¹Ù¸¥ ½ÇÇà ¼ø¼¿¡ µû¶ó µ¥ÀÌÅÍ È帧 ºÐ¼®(data-flow analysis)À» ÅëÇØ »ý¼ºµÈ °¢ °æ·Î¸¦ ±â¹ÝÀ¸·Î ÄÚµåÀÇ ÇöÀç »óŸ¦ ºÐ¼®ÇÏ¿© ÄÚµåÀÇ °áÇÔÀ̳ª Ãë¾àÁ¡À» Á¡°ËÇÏ´Â µµ±¸ÀÌ´Ù.
|
|
|
Á¤ÀûºÐ¼®µµ±¸ – SAP ABAP Ç¥ÁØ Áö¿ø
SAP ABAPÀÇ Á¤ÀûºÐ¼®µµ±¸´Â ÄÄÆÄÀÏ °úÁ¤ ¾øÀÌ ¿ø½Ã ¼Ò½ºÄڵ带 ºÐ¼®Çϰí, Inter-procedural Analysis ±â¼ú ±â¹ÝÀ¸·Î SAPÀÇ ½Å·Ú¼º(ÄÚµù Ç¥ÁØ), ¾ÈÀü¼º(Run-time Error), º¸¾È¼º(º¸¾È Ãë¾àÁ¡)ÀÇ Ç¥ÁصéÀ» ÅëÇÕÁ¡°ËÇÏ´Â Á¤ÀûºÐ¼®µµ±¸ÀÔ´Ï´Ù.
|
|
|
|