Static Analysis for Security

An article from IEEE Security & Privacy magazine.

The article is an accessible introduction to the idea of static code analysis. Several security-related tools are described.

I guess it's tool-week here on LtU what with Dialyzer, JFluid and now this...

Microsoft Fugue

I tried Microsoft Research's Fugue last week. On paper it looks good, but I tried it on a large-scale project of mine and the noise-to-signal ratio was astronomical.