Misha Zitser

dblp:11/4834 · DBLP profile ↗
← Back
1ranked-venue papers
1as first author
0since 2021 · last 2004
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Program analysis · 100%
Network and information security
1 paper
Systems and software security · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability discovery
0.012004
Testing static analysis tools using exploitable buffer overflows from open source code · SIGSOFT FSE 2004
Program analysis › static analysis › vulnerability detection
buffer overflow detection
0.012004
Testing static analysis tools using exploitable buffer overflows from open source code · SIGSOFT FSE 2004
Program analysis › static analysis
static analysis tool evaluation
0.012004
Testing static analysis tools using exploitable buffer overflows from open source code · SIGSOFT FSE 2004
Program analysis
static analysis
0.012004
Testing static analysis tools using exploitable buffer overflows from open source code · SIGSOFT FSE 2004

Methods — techniques the papers use, named apart from their topics

static analysis · 0.1
YearPublicationVenuePosition
2004 Testing static analysis tools using exploitable buffer overflows from open source code
abstract
Five modern static analysis tools (ARCHER, BOON, Poly-Space C Verifier, Splint, and UNO) were evaluated using source code examples containing 14 exploitable buffer overflow vulnerabilities found in various versions of Sendmail, BIND, and WU-FTPD. Each code example included a "BAD" case with and a "OK" case without buffer overflows. Buffer overflows varied and included stack, heap, bss and data buffers; access above and below buffer bounds; access using pointers, indices, and functions; and scope differences between buffer creation and use. Detection rates for the "BAD" examples were low except for Poly-Space and Splint which had average detection rates of 87% and 57%, respectively. However, average false alarm rates were high and roughly 50% for these two tools. On patched programs these two tools produce one warning for every 12 to 46 lines of source code and neither tool appears able to accurately distinguished between vulnerable and patched code.
Misha Zitser, Richard Lippmann, Tim Leek
SIGSOFT FSE1