Çٽɱâ´É

Coverity Static Analysis Technology´Â ÃÖ°íÀÇ Á¤¹Ð¼º°ú È®À强À» ¾à¼ÓÇÕ´Ï´Ù.

- ÀüüÀûÀÌ°í ½Éµµ ±íÀº ºÐ¼®À» ÅëÇØ ¼ÒÇÁÆ®¿þ¾î ¿À·ù¿Í º¸¾È Ãë¾àÁ¡À» °ËÃâÇØ ³À´Ï´Ù.
- ¼ÒÇÁÆ®¿þ¾î°¡ ½ÇÇàµÇ´Â °æ·Î¸¦ 100% Ž»ö, ºÐ¼®ÇÏ¿© »ç¿ëÀÚ°¡ Å×½ºÆ® Çϱâ Èûµç °æ·Î¸¦ ¿Ïº®È÷ ºÐ¼®ÇÕ´Ï´Ù.
- ¼Ò½ºÄÚµå ¶Ç´Â ºôµå °úÁ¤ÀÇ º¯°æ ¾øÀÌ ÀÚµ¿È­µÈ ½ÇÇàÀ» Áö¿øÇÕ´Ï´Ù.
- ¼öõ¸¸ ¶óÀαîÁöÀÇ ´ë±Ô¸ð Äڵ嵵 ºü¸£°Ô ºÐ¼®ÀÌ °¡´ÉÇÕ´Ï´Ù.
- Å×½ºÆ®ÄÉÀ̽º ÀÛ¼º ȤÀº ÇÁ·Î±×·¥ ½ÇÇàÀ» ÇÊ¿ä·Î ÇÏÁö ¾Ê½À´Ï´Ù.
- ¼ÒÇÁÆ®¿þ¾î ¹®Á¦ÀÇ ±Ùº»¿øÀÎÀ» Á¤È®ÇÏ°Ô Ã£¾Æ³»¾î À§Ä¡¸¦ ÆÄ¾ÇÇÕ´Ï´Ù.

 


Interprocedural Data Flow Analysis ¸ðµç °æ·Î¿Í ¸ðµç call chain À» ÅëÇØ Data °ªÀ» ÃßÀûÇÕ´Ï´Ù
False Path Pruning ·±Å¸Àӽà ½ÇÇàÀÌ µÇÁö ¾Ê´Â ÆÐ½º´Â ºÐ¼®¿¡¼­ Á¦¿Ü½ÃÄÑ ºÐ¼®°á°úÀÇ ³ëÀÌÁ °¨¼Ò½Ãŵ´Ï´Ù
Statistical Analysis ¼Ò½ºÄÚµå·ÎºÎÅÍ Á÷Á¢ API »ç¿ë·êÀ» ºÐ¼®ÇÏ¿© ³ª¸ÓÁö ÄÚµåºÎºÐ¿¡¼­ ´Ù¸¥¹æ½ÄÀ¸·Î »ç¿ëµÇ´Â ºÎºÐÀ» üũÇÕ´Ï´Ù

Incremental Analysis µÎ¹øÂ° ºÐ¼®ºÎÅÍ´Â Á÷Á¢ ¼öÁ¤µÈ ÄÚµå ¹× ±×¿¡ µû¹Ù º¯°æµÈ ºÎºÐ¸¸ ºÐ¼®ÇÏ¿© ºÐ¼®½Ã°£À» ´ÜÃàÇÒ¼ö ÀÖ½À´Ï´Ù

 

 


Coverity Prevent ´Â Interprocedural ºÐ¼® ¿£ÁøÀ» ÅëÇØ Äڵ峻ÀÇ ¸ðµç °æ·Î¸¦ ºÐ¼®ÇÏ¿© ´ÙÀ½°ú °°Àº ½Ã½ºÅÛ Àå¾Ö , ÇÁ·Î¼¼½ºÅ©·¡½¬ , ¸Þ¸ð¸® ¹× ¸®¼Ò½º ´©¼ö , ÆÄÀÏ / µ¥ÀÌÅÍ ¼Õ»ó ±×¸®°í ±âŸ ÆÛÆ÷¸Õ½º°ü·Ã ¿À·ù¸¦ °ËÃâÇØ ³À´Ï´Ù .

•  API usage errors
•  Buffer overflow
•  Dangling stack references
•  Flawed branch logic
•  Incorrect allocation sizes
•  Logic errors
•  Memory leaks
•  Non-null terminated strings
•  Null pointer dereferences
•  Out-of-bounds array access
•  Stack overflow
•  Stack smashing
•  Stack string overruns
•  System resource leaks
•  Use of freed resources
•  Use of uninitialized data

Áö¿ø API:

•  Standard C
•  Standard C++
•  Microsoft COM
•  Microsoft Win32

 

 


Coverity Prevent ´Â ´ÙÀ½°ú °°Àº º¸¾È Ãë¾àÁ¡À» °ËÃâÇØ ³À´Ï´Ù .

•  Buffer overflows
•  Cross-site scripting
•  Denial of service
•  File corruption
•  Format string vulnerabilities
•  Improper bounds checking
•  Insecure access control
•  Integer overflows
•  Memory corruption
•  Out-of-bounds array access
•  Privilege escalations
•  SQL injection

Áö¿ø API:

•  Standard C
•  Standard C++

 


µ¿½Ã¼º ¿À·ù´Â Å×½ºÆÃ ´Ü°è¿¡¼­ È®ÀεǴ °æ¿ì°¡ °ÅÀÇ ¾ø°í ½Ç ¿î¿µ¿¡¼­ ³ªÅ¸³ª´Â ƯÈ÷ °ËÃâÇϱ⠾î·Á¿î ¿À·ù·ÎÀÔ´Ï´Ù . Coverity Prevent ´Â µ¥µå¶ô (deadlock) ȤÀº lock À» ´Ù·ç´Â ¹®Á¦ (lock contention) °°ÀÌ ½Ã½ºÅÛ ÆÛÆ÷¸Õ½º¿Í µ¥ÀÌÅÍÀÇ Á¤ÇÕ¼º ¹®Á¦¸¦ À¯¹ßÇÒ¼ö ÀÖ´Â µ¿½Ã¼º ¿À·ù¸¦ °ËÃâÇØ ³À´Ï´Ù .

Áö¿ø API:

•  Pthreads
•  Microsoft Win32
•  WindRiver VxWorks

 


Á¤È®¼º (Accuracy) - Coverity »çÀÇ False Path Pruning, Statistical Analysis µîÀÇ Çõ½ÅÀûÀÎ ¾Ë°í¸®ÁòÀ» ÅëÇØ ¾ç¼º¿À·ùÀÇ ºñÀ²À» 20% ÀÌÇÏ·Î ³·Ãß¾úÀ¸¸ç Ãß°¡ ¼³Á¤ ¹× Æ©´×À» ÅëÇØ ¾ç¼º¿À·ù¸¦ ´õ ³·Ãâ¼ö ÀÖ½À´Ï´Ù .

±íÀÌÀÖ´Â ºÐ¼® (Depth of Analysis) - Coverity Prevent ´Â interprocedural data flow analysis ¿Í statistical analysis ¸¦ ÅëÇØ ÇÁ·Î±×·¥ Àüü¿Í ¸ðµç ÆÐ½º¸¦ ¸Á¶óÇÏ´Â »óÈ£ÀÛ¿ë (interactions) À» ºÐ¼®ÇÕ´Ï´Ù . ´Ù¸¥ °æÀïÅø°ú´Â ´Þ¸® Coverity Prevent ´Â ±Í»çÀÇ Äڵ带 ¿Ïº®ÇÏ°Ô ÀÌÇØÇÏ°í ºÐ¼®ÇÕ´Ï´Ù .

±¤¹üÀ§ÇÑ ºÐ¼® (Breadth of analysis) - Coverity Prevent ´Â ½Ã½ºÅÛÀå¾Ö , ¸Þ¸ð¸®´©¼ö , ºñÁ¤»óÀûÀÎÀÛµ¿ , µ¿½Ã¼º¿À·ù , º¸¾ÈÃë¾àÁ¡ °ËÃâ µîÀÇ ¼ÒÇÁÆ®¿þ¾îÀÇ Ä¡¸íÀûÀÎ ¿À·ù¸¦ ºÐ¼®ÇسÀ´Ï´Ù .

³·Àº ÃѼÒÀ¯ºñ¿ë (Low total cost of ownership) - Coverity Prevent ´Â °³¹ßȯ°æ ȤÀº ÄÚµåÀÇ º¯°æÀÌ ÇÊ¿ä¾øÀÌ ¼ö½ÊºÐ¾È¿¡ ¼³Ä¡°¡ ¿Ï·áµÇ¾î Áï½Ã ÇÁ·Î±×·¥ ±âµ¿ÀÌ °¡´ÉÇÕ´Ï´Ù .

ºÐ¼®¹üÀ§ È®Àå (Extensible) - Coverity Prevent ´Â ±Í»çÀÇ Á¶Á÷ Ư¼º¿¡ ¸Â´Â ¿À·ùüĿ¸¦ Á¤ÀÇÇÏ¿© »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù .

´ë±Ô¸ðºÐ¼® (Massively scalable) - Coverity Prevent ´Â ºôµå½Ã°£ÀÇ 2~4 ¹èÁ¤µµÀÇ ½Ã°£ÀÌ¸é ºÐ¼®ÀÌ ¿Ï·áµÇ¸ç ¼öõ¸¸¶óÀÎÀÇ ÄÚµåÀÇ °æ¿ìµµ ¼ö½Ã°£¾È¿¡ ºÐ¼®ÀÌ ¿Ï·á µË´Ï´Ù .



Á÷ Ã¥ ÀÌ Á¡
False Path Pruning ¿£Áö´Ï¾î¸µ VP/CTOs °³¹ß ¹× Å×½ºÆÃ ¾÷¹«¿¡ÀÇ ÄÚ½ºÆ® Àý°¨
ÇÁ·Î´öÆ®ÀÇ Ç°Áú°ú º¸¾È Çâ»ó
Á¦Ç°Ãâ½Ã±â°£ (time to market) ´ÜÃà
°³¹ß°úÁ¤¿¡¼­ ǰÁú°ú º¸¾ÈÀÇ À§Çèµµ ÆÄ¾Ç
¿£Áö´Ï¾î¸µ ¸Å´ÏÀú /QA ¸Å´ÏÀú °³¹ß°úÁ¤¿¡¼­ ÇÁ·Î´öÆ® ǰÁú °ü¸®
¼öÁ¤µÈ ¹ö±×¿Í »õ·Î ¹ß»ýµÇ´Â ¹ö±×¸¦ ÆÄ¾Ç
¹®Á¦°¡ ¸¹Àº ÆÄÀÏ , ¸ðµâ , ÄÄÆ÷³ÍÆ®¸¦ ÆÄ¾Ç
°³¼±µÈ ÄÚµùÀ» °­Á¦ÇÔÀ¸·Î °³¹ßÀÚÀÇ È¿À² °³¼±
Security ¸Å´ÏÀú °³¹ß°úÁ¤¿¡¼­ º¸¾ÈÀ§Çèµµ °ü¸®
¼Ò½ºÄÚµå , ÄÄÆ÷³ÍÆ® , ÆÄÀϵîÀÇ security risk ÆÄ¾Ç
°³¹ßÀÚ °³¹ß Àü °úÁ¤¿¡¼­ Ä¡¸íÀûÀÎ ¿À·ù ¹× º¸¾ÈÃë¾àÁ¡À» È®ÀÎ
Å×½ºÆ®ÄÉÀ̽º ÀÛ¼º ¹× ¸Å´º¾óÅ×½ºÆ® ¾øÀÌ ¼ÒÇÁÆ®¿þ¾î¸¦ Å×½ºÆ® °¡´É
°¢ ¿À·ù ¿øÀÎÀ» ÆÄ¾ÇÇÏ¿© Áï½Ã ¹ö±×¸¦ ¼öÁ¤°¡´É
Security Auditor °³¹ß ÇÁ·Î¼¼½ºÀÇ ¹æÇؾøÀÌ ¼Ò½ºÄÚµåÀÇ º¸¾ÈÃë¾àÁ¡À» ÆÄ¾Ç °¡´É
º¸¾ÈÃë¾àÁ¡ ¸®Æ÷Æ®¸¦ ÅëÇØ º¸¾ÈÀ§ÇèÀ» ÃßÀû°ü¸®
ÀÚµ¿È­µÈ Äڵ帮ºä¸¦ ÅëÇØ ÄÚµå ÀüüÀÇ ¸ðµç°æ·Î¸¦ ÆÄ¾Ç°¡´É
¼ÒÇÁÆ®¿þ¾î ¾ÆÅ°ÅØÆ® compliance ¸¦ À§ÇÑ ÄÚµù ½ºÅÄ´Ùµå , ³»ºÎ °¡À̵å¶óÀÎ , ÀûÀýÇÑ API ÀÇ »ç¿ë , ¾÷°èÇ¥ÁØ ¹× best practice ¸¦ °­Á¦
ÇÔ¼ö , ÄÄÆÛ³ÍÆ® , ÄÚµå »óÀÇ ¾ÆÅ°ÅØÃ³ ¸ÞÆ®¸¯À» ÃßÀû

 



C/C++ Source Code Analysis

Áö¿øÇ÷§Æû
- Linux
- HPUX
- Windows
- Solaris Sparc
- Solaris X86
- Mac OS X
- FreeBSD
- NetBSD

Áö¿ø C/C++ ÄÄÆÄÀÏ·¯
- Sun CC
- MS Visual Studio
- HPUX compiler
- Intel Compiler for C/C++
- Intel Microsignal Architecture compiler
- GCC / G++
- Arm CC
- Metrowerks CodeWarrior
- Wind River Diab compiler
- TI Code Composer C compiler
- Green Hills compiler
- IAR compiler
- PICC compiler
- ±âŸ ANSI C compatible compilers

Áö¿ø Java ÄÄÆÄÀÏ·¯
- Java JDK (1.4 ÀÌ»ó )

Çϵå¿þ¾î ¿ä°Ç

- 512M ¸Þ¸ð¸® ÀÌ»ó
- 300M + ¼Ò½ºÅ©±âÀÇ 3 ¹èÀÇ µð½ºÅ© °ø°£


 

 
  ¨Ï e-Way Partners All Rights Reserved. Tel: 02-3775-2657 E-mail: hschung@ewaypartners.com
Home | Product | Customer | Support | About us