Talk With an Expert

Risk Management with Automated Feature Analysis of Software Components

Risk Management with Automated Feature Analysis of Software Components (PDF, 2.30MB)Published: 27 Aug, 2020
Created by:
Steven Launius

Organizations developing software need pragmatic risk management practices to prevent malicious code from contaminating their software. Traditional security tools for Static Code Analysis identify vulnerabilities, not the presence of backdoors exhibiting unintended actions. Application Inspector is a Microsoft tool released to the open source community that identifies risky features and characteristics of source code libraries. This research will evaluate the accuracy of feature detection in the Application Inspector tool and construct a risk model for automating decisions based on feature analysis of source code.