Computer Science ›› 2016, Vol. 43 ›› Issue (5): 76-79, 107.doi: 10.11896/j.issn.1002-137X.2016.05.014

Novel Taxonomy of Security Weakness in Source Code Based on Three-dimension Tree Model

ZHANG Yan, LI Zhou-jun, DONG Guo-wei and MA Dian-fu   

  • Online:2018-12-01 Published:2018-12-01

Abstract: We presented a novel taxonomy of security weakness in source code based on three-dimension tree model,which synthetically considers the three aspects:the causes of the defect,the results and its form of expression.Case studies show that compared with CWE and Fortify,the taxonomy in this paper is more accurate and detailed.This paper is not only helpful to establish a kind of relatively complete source code defect classification system,but also very signi-ficant in practice to refine the rules of the security weakness detection.

Key words: Three-dimension tree model,Source code,Security weakness,Taxonomy

