References
- "Common Vulnerabilities and Exposures," http://cve.mitre.org/
- "Common Weakness Enumeration," http://cwe.mitre.org/
- Gray McGraw, "Software Security: Building Security in," Addison-Wesley, 2006
- "CERT," http://www.cert.org/
- Ivan Arce, Elias Levy, "The rising threat of vulnerabilities due to integer errors," Security & Privacy, IEEE, 2003. 8
- Alef One, "Smashing The Stack For Fun And Profit," Phrack Magazine, Vol. 7, No. 49. 1996
- 행정안전부, "전자정부 소프트웨어 개발.운영자를 위한 소프트웨어 개발보안 가이드," 행정안전부, 2012. 5
- 행정안전부, "정보시스템 구축 운영 지침(행정안전부고시 제2011-36호)," 행정안전부, 2012. 9
- "고려대, '소프트웨어 개발보안 연구센터,' 선정," http://www.newswire.co.kr/newsRead.php?no=624730
- "Red Hat Bugzilla,", https://bugzilla.redhat.com/
- "Coverity Prevent," http://www.coverity.com/
- "HP Fortify Static Code Analyzer," http://www8.hp.com/us/en/software-solutions/static-code-analysis-sast/
- "Klockwork," http://www.klockwork.com/
- "LDRA Software Technology," http://www.ldra.com/
- "CodeSonar," http://www.grammatech.com/codesonar
- "Sparrow," http://www.fasoo.com/site/fasoo/sourcecodeanalysis/sparrow.do
- "SecurityPrism," http://www.gtone.co.kr/main/ag/sp.php
- "ROSE compiler infrastructure," http://rosecompiler.org/
- "Splint-Secure Programming Lint," http://www.splint.org/
- "CppCheck," http://cppcheck.sourceforge.net/
- "Clang Static Analyzer," http://clang-analyzer.llvm.org/
- "PMD," http://pmd.sourceforge,net/
- "Findbugs," http://findbugs.sourceforge,net/
- Godefroid, Patrice, Michael Y. Levin, and David A. Molnar. "Automated Whitebox Fuzz Testing." PLDI'08, Tucson, USA, July 2008
- 방지호, 하란, "소프트웨어 보안약점 기반의 오픈소스 보안약점 진단도구 분석," 한국정보과학회 2013 한국컴퓨터종합학술대회, 2013. 6
- "NIST SAMATE," http://samate.nist.gov/
- "ISO/IEC TS 17961:2013 Information technology --Programming languages, their environments and system software interfaces -- C secure coding rules," http://www.iso.org/iso/