Static analysis tool binaries identifies security vulnerabilities in third-party executables

By eeNews Europe

Because the technology does not rely on debug or symbol-table information, it can examine the stripped executables normally shipped by software vendors. As a result, users can use CodeSonar for Binaries to perform a security analysis on software without any cooperation from the vendor. The analysis engine is the result of a 10-year collaboration between GrammaTech and the University of Wisconsin-Madison, involving 21 experts in program analysis and $15 million in research and development (R&D). Because the tool analyses the software that users actually run, the specific machine code to be run on the processor, it can detect problems introduced not only by programmers, but also by the compiler and other tools in the development chain.

