<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Detecting Code Security Breaches by Means of Dataflow Analysis</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sergei Borzykh</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alexey Markov</string-name>
          <email>a.markov@bmstu.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Valentin Tsirlov</string-name>
          <email>v.tsirlov@bmstu.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Development Department NPO Echelon</institution>
          ,
          <addr-line>JSC</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Information Security Department Bauman Moscow State Technical University Moscow</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Moscow</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Testing Department NPO Echelon</institution>
          ,
          <addr-line>JSC</addr-line>
        </aff>
      </contrib-group>
      <fpage>15</fpage>
      <lpage>20</lpage>
      <abstract>
        <p>-We discuss static and dynamic methods of the code analysis. A new approach to the static analysis method based on command flow graphs is presented. Practical cases and implementations of this dataflow approach are given.</p>
      </abstract>
      <kwd-group>
        <kwd>information security</kwd>
        <kwd>software security</kwd>
        <kwd>static analysis</kwd>
        <kwd>heuristic analysis</kwd>
        <kwd>vulnerabilities</kwd>
        <kwd>defects</kwd>
        <kwd>production models</kwd>
        <kwd>data-flow analysis</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>
        IT-based solutions are currently used everywhere, and
significant problems are represented by both internal software
errors of the information systems, and malicious source code
implemented in the information system software. The
consequences of both problems lead to violation of access,
integrity and confidentiality of the processed information,
which can result in financial and reputational losses of the
business. This is a reason of growing financial losses over the
last few years. High quality and failure-free operation of the
source code is a burning issue of the software industry. Ever
growing complexity of the software complexes, their use in the
management and control systems of the government and the
industrial production require continuous upgrading of the
software testing and control methods [
        <xref ref-type="bibr" rid="ref1 ref11 ref12 ref2 ref3">1-11</xref>
        ].
      </p>
      <p>II.</p>
    </sec>
    <sec id="sec-2">
      <title>STATIC AND DYNAMIC METHODS OF THE CODE</title>
      <p>ANALYSIS</p>
      <p>
        Upon the whole, the testing methods used in the audit of the
software systems security may be divided into two groups:
static methods (structural testing) and dynamic methods
(functional testing). Static methods of the code analysis, which
do not require running of the analysed code for its operation,
allow for full or partial automation [
        <xref ref-type="bibr" rid="ref13 ref14">12, 13</xref>
        ]. Such methods are
most frequently used in case of full access to the software
system and its source texts, which is called “a white-box
technique”. It employs source and loading modules of the
program and its component. The benefit of the static code
analysis is that it does not require multiple program runs under
various operational conditions (condition of the environment
and input data) and possibility to achieve a greater degree of
automation of the tests for the program defects based on their
design features. When developing software for special-purpose
informational systems, these methods are used to search for
random code defects, and hidden software functionality
(backdoors) [
        <xref ref-type="bibr" rid="ref15 ref16">14, 15</xref>
        ].
      </p>
      <p>
        Dynamic software analysis is a method of analysis that
stipulates program running on real or virtual processor [
        <xref ref-type="bibr" rid="ref17">16</xref>
        ].
Functional testing is most in demand during the study of the
programs by black box method, when there is access to only
external software interfaces without account of their structure,
back-end interfaces or status. The approach is used to study
accuracy and stability of the software operation within the
framework of the key jobs of the test engineers, however, the
method is not always effective for searching of errors related to
combinations of rarely used input data, and for identifying
intentional backdoors there. Static analysis of the software
source texts is closely related to development of compilation
systems, and many approaches of static analysis use elements
of the compiler theory, namely, the code view models [
        <xref ref-type="bibr" rid="ref18 ref19">17, 18</xref>
        ].
      </p>
      <p>III.</p>
    </sec>
    <sec id="sec-3">
      <title>SIGNATURE ANALYSIS AS THE MAIN METHOD</title>
      <p>
        The approach that is called signature analysis implies the
search for software defects in the software code by comparing
code fragments with the samples from the database of templates
(signatures) of the security defects. Depending on the method
for correlating fragments of the code to the template, and the
intermediate representation in use, there may be algorithms of
searching for a substring in the string, and query language for
structured information (for instance, XQuery for XML), or
specially designed methods of correlation, but in each case each
of the signatures represents the decision procedure, which
employs various presence bits of potentially harmful structure.
[
        <xref ref-type="bibr" rid="ref19">18</xref>
        ] provides examples of the rules for generating error
signatures, which correspond to the CWE standard. We can see
here that the signature methods are not limited to the types of
defects and are preferable, when dealing with the backdoors.
      </p>
      <p>
        Improvement of the operational qualities of the static code
analysis is mainly related to minimizing the number of “false
positives” while preserving maximum fullness of the list of the
types of potentially harmful structures [
        <xref ref-type="bibr" rid="ref20">19</xref>
        ]. Therefore, the
instruments describing signatures of the code defects shall
ensure maximum flexibility in defining a defect with account of
diversity in the syntax of the programming language under
study.
      </p>
      <p>
        The field for designing means of static analysis is now
actively developing: new directions of analysis do not force out
the reputable approaches, on the contrary, they complement
them by integrating the advantages of the predecessors. For
instance, such approach as dataflow analysis may compensate
for the drawbacks of the template-based code defect search,
which does not allow for high quality of identification of
SQL, Path-, XSS-injections, and other types of code injections,
however, it will require large RAM and computing resources of
the processor [
        <xref ref-type="bibr" rid="ref21 ref22 ref23">20, 21, 22</xref>
        ].
      </p>
      <p>
        An interesting manifestation of symbiosis of the analysis
methods is when potentially harmful structures, which have
been initially identified by the customary signature method is
supported by the automated method using highly-specialized,
costly, but efficient procedures [
        <xref ref-type="bibr" rid="ref24 ref25 ref26">23-25</xref>
        ].
      </p>
      <p>IV.</p>
      <p>DATAFLOW ANALYSIS</p>
      <p>
        The dataflow analysis can be described as a process of
gathering information about the use, defining and dependency
of data in the analysed program [
        <xref ref-type="bibr" rid="ref27 ref28">26, 27</xref>
        ]. The dataflow analysis
uses command flow graph generated based on the code tree.
This graph represents all possible paths for running this
program: the nodes stand for ‘linear’, consecutive fragments of
the code without any transitions, and the edges stand for
potential transfer of control between these fragments.
      </p>
      <p>
        Syntactic analysis allows for identifying control structures,
such as procedure, function or method calls, which, in their
turn, allow building call graphs, control flow graphs, and
identifying assignation and the others that allow building
dataflow graphs [
        <xref ref-type="bibr" rid="ref18 ref19 ref29">17, 18, 28</xref>
        ]. Control and dataflow graphs are
used for analysis of the local program blocks (mainly, the
content of the functions, procedures and methods - local
analysis). Control flow graphs allow analysing program
behaviour on a more general level (on the level of the file,
module or the entire program - global analysis).
      </p>
      <p>The dataflow analysis can be used for proper detection of
certain types of defects (as a rule, in operation) with a minimum
number of false positives: SQL-, command-, XSS-injections,
other types of code injections and setting directly in the code of
the authentication data. It should be noted that despite the
differences in these defects, most of them implement the
following defect use pattern.</p>
      <p>1.</p>
      <p>Data is received from the user (consequently,
untrusted data).</p>
      <p>Data propagates through the program depending on the
conditions and cycles.</p>
      <p>Data is transformed, or filtered, or remains unchanged.
Finally, untrusted data gets access to the vulnerable
function (buffer management, SQL query running
etc.).</p>
      <p>
        There is a mechanism for dataflow analysis called “taint
propagation”, which allows for identifying the defect, but also
shows the data propagation path, starting from the entry point
(user input), through the program and to the function
vulnerability [
        <xref ref-type="bibr" rid="ref30">29</xref>
        ]. An interesting instance of such mechanism
of dataflow analysis is “constant propagation” - search for
authentication data (login, password, IP-address) directly in the
software source code. Let us review a code fragment:
String login = "Some Constant";
      </p>
      <p>Such code fragment can be sought using signature analysis
(search as per templates). It only requires representation rule:
VARIABLE (“login” OR “password”)
OPERATOR (“=”) CONSTANT(*);</p>
      <p>However, these code fragments can show that such code
was written for debugging and remained in the final software
version by accident, or was added intentionally, provided there
was assurance that the code would not be inspected. If a
malicious developer wants to hide the imbedded defect from the
person, who inspects the code, but also from the means of static
analysis, the code may be written, for instance, this way:
String label = "somewhere".substring(0,4);
String summ =
LogConstant.class().getClassName().toLowerCase()
;</p>
      <p>String upd_time = summ.substring(3,
summ.lenght()-3);</p>
      <p>Char ascii_conv = 95;
String login = label + ascii_conv + upd_time;
If we break down parts of code fragment into various
modules and files of source texts, it will be next to impossible
to identify the defect using manual analysis, as well as many
known automated methods.</p>
      <p>The “constant propagation” mechanism of the dataflow
analysis may define the values of the variables, their
concatenation and transfer into other variables, and final values
of the variables. As a result, the defect may be identified and,
consequently, unauthorized access to the functional capabilities
of the software may be prevented.
• Untrusted data - data received from interfaces outside
the analysed code and trusted zone (allied agents, users);</p>
      <p>Critical flow - flow from the entry point to the touch
Let us define the general procedure for the search for
undocumented features using dataflow analysis:</p>
      <p>Prepare source texts and configurations of the analysed
software.</p>
      <p>Use of the static analysis tools (that implement
dataflow analysis) to sourced texts and configurations
prepared in step 1.</p>
    </sec>
    <sec id="sec-4">
      <title>Processing of the results of analysis: • • •</title>
    </sec>
    <sec id="sec-5">
      <title>Selecting suspicious dataflow paths, Analysing entry points and points of untrusted data propagation, Filtering false positives.</title>
      <p>1.
2.</p>
    </sec>
    <sec id="sec-6">
      <title>Drawing up the final report.</title>
      <p>Dataflow analysis is divided into two stages. The first stage
of analysis requires engineering of critical control and
dataflows in the analysed software. Below is the sequence of
the algorithm actions.</p>
      <p>Search for the entry points of the untrusted data in the
analyzed software (template-based search). This step
requires a base of entry points templates formed by
inspections of standard libraries and popular
frameworks.</p>
      <p>Search for the points that contain potentially
vulnerable functions (template-based search as well).
For each entry point of the untrusted data, add
function, method and procedure calls that are
happening in this point to the control flow tree.</p>
      <p>Repeat clause 3 until you reach one of the final points
specified in clause 2, or until you reach a point that
does not transition into other functions, procedures or
methods.</p>
      <p>Once control flow trees are built, identify flows that
have reached potentially vulnerable functions.</p>
      <p>Consider these flows critical.</p>
      <p>At the second stage, analyse critical control flows, their
separate points (functions, procedures and methods) and
identify the fact of untrusted data propagation from the entry
point to the potentially vulnerable function. Below is the
sequence of the algorithm actions:</p>
      <p>Obtain entry point (function, procedure or method),
engineer all dataflows that affect the data received
from untrusted source.</p>
      <p>If untrusted data after interaction with other dataflows
has not changed its status, proceed to clause 3.
Otherwise, complete analysis of the current critical
control flow.</p>
      <p>If untrusted data were transmitted at the following
point of the critical control flow, proceed to clause 4.
Otherwise, complete analysis of the current critical
control flow.</p>
      <p>If the current point is the endpoint, proceed to clause
5. Otherwise, proceed to clause 2 with a new point and
new input data. Continue, until analysis of all points in
the critical control flow is complete.</p>
      <p>If the current point is the endpoint, and untrusted data
were transmitted to the potentially vulnerable function
from the first point, enter the critical control flow on
the positive triggering list. Otherwise, finalize analysis
of the current critical control flow.</p>
    </sec>
    <sec id="sec-7">
      <title>On creating data;</title>
    </sec>
    <sec id="sec-8">
      <title>On saving data;</title>
    </sec>
    <sec id="sec-9">
      <title>On destruction of data.</title>
      <p>The list obtained at the entry to the second stage of analysis
is transferred to the entry of the report generator, which control
interface is also present within the graphical user interface; after
that the report generator based on the transferred list and
database of the defect types draws up a report on the performed
static analysis.</p>
      <p>VI.</p>
    </sec>
    <sec id="sec-10">
      <title>LOCAL ANALYSIS</title>
      <p>The following description refers to dataflow
implementation in static analyzer AppChecker developed by
NPO Echelon. The local analysis is normally performed for a
certain block of the code (which coincides with the visibility
scope depending on the programming language). The local
analysis assumes obtaining information about the conditions of
the program in all points of the program, i.e.:</p>
      <p>The diagram of the local analysis algorithm can be seen in
Figure 1.</p>
      <p>You can optionally store, for instance, data on the value
constancy (for the “constant propagation” tool), data assurance
flag (for “taint propagation”), and information about the
condition of the variable.</p>
      <p>Information can be obtained from the local block in two
opposite ways listed below:</p>
      <p>From bottom to top: from the point susceptible to the
defect make assumptions about the properties of the
data transmitted into it, go up the code to the point of
entry in the local area (function, procedure or method).
The approach requires consideration of all options of
the program run (for each branch and iteration of the
cycles), which leads to “combinatorial explosion” of
the information quantity, which shall be stored during
analysis.</p>
      <p>From top to bottom — from the point of entry of
untrusted data into the program, down along the code,
with available information about all of the above
points of the program. This approach allows making
assumptions about running separate branches of the
program and engineer sequential analysis. The
drawback of this approach is difficulty in obtaining the
path from the entry point to the exit point, because the
only known fact is that the path exists.</p>
      <p>Information that is available within one function
(procedure, method), as a rule, is insufficient for high quality
search for the defects, because many defects propagate
throughout the project, or, at least one file. Global analysis is
used to link data received from different functions. The global
analysis engages call graphs. To ensure operation of this
analysis it is sufficient to obtain certain confirmation or
assumption about the properties of input and output data of
separate functions in the call graph. It is important to obtain
such data in the context of the functions, which are outside of
the path from the point of the data entry to the point susceptible
to the defects, and which analysis is necessary because the call
of such functions may change the arguments or return values,
which properties may depend on the properties of the input data
(for instance, the substring get function, which accepts data
input by the user returns taint data, although formally it is not
included in the call graph).</p>
      <p>The diagram of the global analysis algorithm can be seen in
Figure 2.</p>
    </sec>
    <sec id="sec-11">
      <title>MATHEMATICAL DESCRIPTION OF THE DATAFLOW</title>
      <p>ANALYSIS</p>
      <p>The ideal solution of the dataflow analysis task from the
theoretical point of view consists in the search for all possible
paths. Let us introduce certain symbols: B — data block for
analysis, which consists from elementary subblocks B1, …, Bn.
It is a known fact, that the dataflow values before the statement
and after it are limited by the semantics of the instruction. The
correlation between the dataflow values before and after the
assignment statement is characterized by the transfer function.
fi shall stand for a transfer function of block Bi, which
characterizes transformation of data in this block. The values of
the dataflow before and after subblock Bi shall be represented
as IN[Bi] (OUT[Bi] accordingly).</p>
      <p>Suppose P is a possible execution path in the flow graph:</p>
      <p>P= Input → B1 → … → Bk.</p>
      <p>In this case, the transfer function fP for path P will be
represented by a composition of the transfer functions fk−1•…•f1.
However, it should be noted that fk is not a part of the
composition, which shows that the path reached the start of
subblock Bk, but not its end. Let us consider that any flow graph
consists of two empty subblocks - input block, which is a start
point of the graph, and output block, which is passed by all exits
from the graph. The transfer functions of input and output
blocks are represented by constant values.</p>
      <p>Thus, taking into account the foregoing, the ideal solution is
the array:</p>
      <p>( ) = ⋃   (  ),
where   is the result of the constant transfer function,
which is represented by the starting input node.</p>
      <p>It may seem that the task of the search for the ideal solution
is reduced to analysis of the transfer functions fP for all paths P
in the flow graph. However, it was noted by Ullmann [17, page
724], the task of the search for the ideal solution is generally
unsolvable. If block B has branches, cycles and recursions,
array IDEAL[B] maybe unlimited. The assistance comes from
the solution of path-based gathering [17, page 757], which is
similar to the path search algorithm in the graph, so called
‘breadth first search’. This algorithm allows achieving such
final number of P, that an array of all fP covers all unique
transformations of fB.</p>
      <p>1. Potential SQL-injection is identified in Dolibarr
project, in htdocs/admin/menus/edit.php file:</p>
      <p>Let us write down an iterative solution to the generalized
task for the dataflow. There are two versions of such
algorithm - direct and reverse. The first version proceeds from
input blocks to the output, the second - goes in the reverse. The
basis is Ullmann’s algorithm [17, page 754].</p>
    </sec>
    <sec id="sec-12">
      <title>Direct version of the algorithm:</title>
      <p>OUT[INPUT] =   ;
For (each base block B, which differs from input)</p>
      <p>OUT[B] = InitDataConst;
while (changes are entered in OUT)</p>
      <p>for (each basic block B, which differs from input)
{
{
IN[B] = ⋃P-predecessor OUT[P] ;</p>
      <p>OUT[B] = fB (IN[B]);
}
Reverse version of the algorithm:
IN[INPUT] = voutput;
for(each basic block B, which differs from output)</p>
      <p>IN[B] = InitDataConst;
while (changes are entered in IN)
for(each basic block B, which differs from output)
OUT[B] = ⋃P-predecessor B IN[P] ;
IN[B] = fB (OUT[B]);
}</p>
      <p>
        Subject to [
        <xref ref-type="bibr" rid="ref18">17</xref>
        ], if algorithm converges, its result is the
solution to the dataflow problem. The obtained solution turns
out to be a so called maximum fixed point, which has the
property that in any other solution IN[B] and OUT[B] are
already present in this solution. If in this case the analysed block
is final, the convergence of the algorithm is guaranteed. These
statements are proved by Jeffrey Ullmann in [17, pages
754755].
      </p>
      <p>It should be noted that in practice it is inadvisable to analyse
all data used by the program. For example, if we consider
unfiltered user input as input data vinput, we are going to be
interested in B, where OUT[B] are entered in the database or
output in HTML-context. Block B may also be represented by
the function of the input information filtering, thus finalizing
the path and marking it as safe.</p>
      <p>IX.</p>
      <p>EXAMPLES AND RESULTS</p>
      <p>Dataflow analysis is widely spread in compilers and some
sort of program analysis tools in order to find mistakes, typos
and other accidentally inserted source code errors or
weaknesses. This paper is dedicated to the implementation and
usage of well-known analysis approach for detecting potentially
harmful code areas deliberately inserted into source code. The
paper subject novelty is in joint usage dataflow and signature
template-based analysis for detection both embedded malicious
code (backdoors, trapdoors, hard-code credentials) and
weaknesses caused by accidental developer's mistakes.</p>
      <p>Below are the examples of potentially harmful structures
detected by the method described here using AppChecker
software. These examples are real but quite simple because we
think it is unacceptable to provide big and complex examples in
this article.</p>
      <p>B284 = «$sql = "SELECT m.rowid, m.mainmenu, m.level,
m.langs FROM ".MAIN_DB_PREFIX."menu as m WHERE
m.rowid = ".$_GET[’menuId’];»
B285 = «$res = $db-&gt;query($sql);»</p>
      <p>Data received from the user is entered in $sql variable, and
the value of the variable without filtration is entered in
SQLrequest, which may lead to running of random SQL code. The
critical point is string B285; constant string is concatenated with
taint data, and as a result the part of the string to the right of
concatenation becomes taint.</p>
      <p>2. The use of passwords set directly in the software code
is identified in AWCM project, in connect.php file:
B3 = «$db_hostname = "localhost";»
B4 = «$db_username = "root";»
B5 = «$db_userpass = "123456";»
B6 = «$db_database = "awcm";»
B24 = «@mysql_connect($db_hostname, $db_username,
$db_userpass);»</p>
      <p>
        Parameters, including the password, set directly in the code,
are used to connect to the database. The critical point is string
B24; in string B5 the right part of the expression is a constant; in
practice, the string is allocation of constant value to the variable
used further to set the password. Nowadays AppChecker, which
implements algorithms of signature analysis using flow
analysis, contains the total of 253 rules for the search of defects
in the software code in four programming languages: С/С++,
Java, PHP, C#; the rules allow identifying 113 types of defects
[
        <xref ref-type="bibr" rid="ref29 ref31">28, 30</xref>
        ]. AppChecker was tested in 90 projects with open
source codes.
      </p>
    </sec>
    <sec id="sec-13">
      <title>X. CONCLUSION</title>
      <p>The following conclusions can came from the results of the
study:</p>
      <p>1. Based on well-reputed signature analysis approach,
the suggested method of the dataflow analysis can minimize the
number of false positives and simplify the development of
signatures for an analyser production model.</p>
      <p>
        2. The suggested method and tools will be useful for the
accredited testing laboratories as well as developers of safe
software tools. Secure software development practices (we
would, first of all, like to mention a recently approved national
standard in this field [
        <xref ref-type="bibr" rid="ref32 ref33 ref34">31-33</xref>
        ]), are being implemented at a
growing rate nowadays, therefore integration of the structured
testing procedure in the process of the automated system
development based on static signature analysis is a high-priority
task.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>D.</given-names>
            <surname>Yu. Volkanov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.A.</given-names>
            <surname>Zakharov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.A.</given-names>
            <surname>Zorin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.V.</given-names>
            <surname>Podymov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.V.</given-names>
            <surname>Konnov</surname>
          </string-name>
          , “
          <article-title>A Combined Toolset for the Verification of Real-Time Distributed Systems,”</article-title>
          <string-name>
            <surname>Program. Comput. Softw.</surname>
          </string-name>
          , vol.
          <volume>41</volume>
          , no.
          <issue>6</issue>
          , pp.
          <fpage>325</fpage>
          -
          <lpage>335</lpage>
          ,
          <year>November 2015</year>
          . DOI:
          <volume>10</volume>
          .1134/S0361768815060080.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>I. S.</given-names>
            <surname>Zakharov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. U.</given-names>
            <surname>Mandrykin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. S.</given-names>
            <surname>Mutilin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E. M.</given-names>
            <surname>Novikov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. K.</given-names>
            <surname>Petrenko</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A. V.</given-names>
            <surname>Khoroshilov</surname>
          </string-name>
          , “
          <article-title>Configurable toolset for static verification of operating systems kernel modules</article-title>
          ,
          <source>” Program. Comput. Softw.</source>
          , vol.
          <volume>41</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>49</fpage>
          -
          <lpage>64</lpage>
          ,
          <year>January 2015</year>
          . DOI:
          <volume>10</volume>
          .1134/S0361768815010065.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>I. S.</given-names>
            <surname>Anureev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.V</given-names>
            <surname>Maryasov</surname>
          </string-name>
          , and
          <string-name>
            <given-names>V.A.</given-names>
            <surname>Nepomniaschy</surname>
          </string-name>
          , “
          <article-title>C-programs verification based on mixed axiomatic semantics</article-title>
          ,
          <source>” Autom. Control Comput. Sci.</source>
          , vol.
          <volume>45</volume>
          , no.
          <issue>7</issue>
          , pp.
          <fpage>485</fpage>
          -
          <lpage>500</lpage>
          ,
          <year>2011</year>
          . January
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <given-names>P. N.</given-names>
            <surname>Devyanin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. V</given-names>
            <surname>Khoroshilov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. V</given-names>
            <surname>Kuliamin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. K.</given-names>
            <surname>Petrenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>and I. V</given-names>
            <surname>Shchepetkov</surname>
          </string-name>
          , “
          <article-title>Formal Verification of OS Security Model with Alloy</article-title>
          and
          <string-name>
            <surname>Event-B BT - Abstract State</surname>
            <given-names>Machines</given-names>
          </string-name>
          , Alloy,
          <string-name>
            <surname>B</surname>
          </string-name>
          ,
          <string-name>
            <surname>TLA</surname>
          </string-name>
          , VDM, and
          <string-name>
            <surname>Z</surname>
          </string-name>
          : 4th International Conference,
          <string-name>
            <surname>ABZ</surname>
          </string-name>
          <year>2014</year>
          , Toulouse, France, June 2-6,
          <year>2014</year>
          . Proceedings,”
          <string-name>
            <given-names>Y.</given-names>
            <surname>Ait Ameur and K.-D.</surname>
          </string-name>
          Schewe, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg,
          <year>2014</year>
          , pp.
          <fpage>309</fpage>
          -
          <lpage>313</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <source>Applications and Case Studies: 5th International Symposium, ISoLA</source>
          <year>2012</year>
          , Heraklion, Crete, Greece,
          <source>October 15-18</source>
          ,
          <year>2012</year>
          , Proceedings,
          <string-name>
            <surname>Part</surname>
            <given-names>II</given-names>
          </string-name>
          ,”
          <string-name>
            <given-names>T.</given-names>
            <surname>Margaria</surname>
          </string-name>
          and
          <string-name>
            <given-names>B.</given-names>
            <surname>Steffen</surname>
          </string-name>
          , Eds. Berlin, Heidelberg: Springer Berlin Heidelberg,
          <year>2012</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>E. di Bella</surname>
          </string-name>
          , I. Fronza,
          <string-name>
            <given-names>N.</given-names>
            <surname>Phaphoom</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sillitti</surname>
          </string-name>
          , G. Succi, and
          <string-name>
            <given-names>J.</given-names>
            <surname>Vlasenko</surname>
          </string-name>
          , “
          <article-title>Pair Programming</article-title>
          and
          <string-name>
            <surname>Software Defects--A Large</surname>
          </string-name>
          ,
          <source>Industrial Case Study,” IEEE Transactions on Software Engineering</source>
          , vol.
          <volume>39</volume>
          , no.
          <issue>7</issue>
          . pp.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          930-
          <fpage>953</fpage>
          , Jul.
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Avdoshin</surname>
          </string-name>
          and
          <string-name>
            <given-names>E. Y.</given-names>
            <surname>Pesotskaya</surname>
          </string-name>
          , “
          <article-title>Software risk management,” 2011 7th Central and Eastern European Software Engineering Conference (CEE-SECR)</article-title>
          . pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          <string-name>
            <given-names>A. S.</given-names>
            <surname>Kamkin and M. M. Chupilko</surname>
          </string-name>
          , “
          <article-title>Survey of modern technologies of simulation-based verification of hardware,”</article-title>
          <string-name>
            <surname>Program. Comput. Softw.</surname>
          </string-name>
          , vol.
          <volume>37</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>147</fpage>
          -
          <lpage>152</lpage>
          . May
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          <string-name>
            <given-names>G.</given-names>
            <surname>Reber</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Malmquist</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Shcherbakov</surname>
          </string-name>
          . “
          <article-title>Mapping the application security terrain,” Voprosy kiberbezopasnosti [Cybersecurity Issues]</article-title>
          , No 1, pp.
          <fpage>36</fpage>
          -
          <lpage>39</lpage>
          .
          <year>January 2014</year>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2014-2-
          <fpage>36</fpage>
          -39.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>A.</given-names>
            <surname>Kozachok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bochkov</surname>
          </string-name>
          .,
          <string-name>
            <given-names>T. M.</given-names>
            <surname>Lai</surname>
          </string-name>
          and
          <string-name>
            <surname>E. Kochetkov.</surname>
          </string-name>
          “
          <article-title>First Order Logic for Program Code Functional Requirements Description,” Voprosy kiberbezopasnosti [Cybersecurity issues]</article-title>
          .
          <source>No</source>
          <volume>3</volume>
          (
          <issue>21</issue>
          ), pp.
          <fpage>2</fpage>
          -
          <lpage>7</lpage>
          .
          <year>August 2017</year>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2017-3
          <issue>-2</issue>
          -7.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>E. G.</given-names>
            <surname>Vorobiev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. A.</given-names>
            <surname>Petrenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I. V.</given-names>
            <surname>Kovaleva</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I. K.</given-names>
            <surname>Abrosimov</surname>
          </string-name>
          . “
          <article-title>Organization of the entrusted calculations in crucial objects of informatization under uncertainty,”</article-title>
          <source>The 20th IEEE International Conference on Soft Computing and Measurements (SCM</source>
          <year>2017</year>
          ), pp.
          <fpage>299</fpage>
          -
          <lpage>300</lpage>
          . May
          <year>2017</year>
          . DOI:
          <volume>10</volume>
          .1109/SCM.
          <year>2017</year>
          .
          <volume>7970566</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>A.</given-names>
            <surname>Cox</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.-Y.E. Chang X.</given-names>
            <surname>Rival</surname>
          </string-name>
          .
          <article-title>"Automatic Analysis of Open Objects in Dynamic Language Programs,"</article-title>
          <source>International Static Analysis Symposium, Static Analysis</source>
          , pp.
          <fpage>134</fpage>
          -
          <lpage>150</lpage>
          ,
          <year>September 2014</year>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -10936-
          <issue>7</issue>
          _
          <fpage>9</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>G.</given-names>
            <surname>Balatsouras</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Smaragdakis</surname>
          </string-name>
          .
          <article-title>"Structure-Sensitive Points-To Analysis for C and C++"</article-title>
          ,
          <source>International Static Analysis Symposium, Static Analysis</source>
          , pp.
          <fpage>84</fpage>
          -
          <lpage>104</lpage>
          ,
          <year>September 2016</year>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>662</fpage>
          -53413-
          <issue>7</issue>
          _
          <fpage>5</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>F.</given-names>
            <surname>Zhu</surname>
          </string-name>
          ,
          <string-name>
            <surname>J. Wei.</surname>
          </string-name>
          “
          <article-title>Static analysis based invariant detection for commodity operating systems</article-title>
          ,
          <source>” Computers and Security</source>
          , vol.
          <volume>43</volume>
          , pp.
          <fpage>49</fpage>
          -
          <lpage>63</lpage>
          ,
          <year>June 2014</year>
          . DOI:
          <volume>10</volume>
          .1016/j.cose.
          <year>2014</year>
          .
          <volume>02</volume>
          .00.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>M.</given-names>
            <surname>Bradley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Cassez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Fehnker</surname>
          </string-name>
          ,
          <string-name>
            <surname>T.</surname>
            Given-Wilson,
            <given-names>R. Huuck. “</given-names>
          </string-name>
          <article-title>High performance Static Analysis for Industry,”</article-title>
          <source>Electronic Notes it Theoretical Computer Science</source>
          , vol.
          <volume>289</volume>
          , pp.
          <fpage>3</fpage>
          -
          <issue>14</issue>
          ,
          <year>December 2012</year>
          . DOI:
          <volume>10</volume>
          .1016/j.entcs.
          <year>2012</year>
          .
          <volume>11</volume>
          .002.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>P.</given-names>
            <surname>Gonzalez-de-Aledo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Sanchez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Huuck</surname>
          </string-name>
          .
          <article-title>"An Approach to StaticDynamic Software Analysis,"</article-title>
          <source>Proceedings of International Workshop on Formal Techniques for Safety-Critical Systems</source>
          , pp.
          <fpage>225</fpage>
          -
          <lpage>240</lpage>
          , November,
          <year>2015</year>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -29510-7_
          <fpage>13</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>A.V.</given-names>
            <surname>Aho</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.S.</given-names>
            <surname>Lam</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. Sethi J.D.</given-names>
            <surname>Ullman</surname>
          </string-name>
          . Compilers: Principles, Techniques, and
          <article-title>Tools (2nd Edition)</article-title>
          .
          <source>Addison Wesley; 2nd edition (September</source>
          <volume>10</volume>
          ,
          <year>2006</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>A.S.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.A.</given-names>
            <surname>Fadin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.L.</given-names>
            <surname>Tsirlov</surname>
          </string-name>
          . “
          <article-title>Multilevel Metamodel for Heuristic Search of Vulnerabilities in the Software Source Code</article-title>
          ,”
          <source>International Journal of Control Theory and Applications</source>
          . V.
          <article-title>9</article-title>
          . N 30, pp.
          <fpage>313</fpage>
          -
          <lpage>320</lpage>
          ,
          <year>December 2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>M.</given-names>
            <surname>Junker</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Huuck</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Fehnker</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Knapp</surname>
          </string-name>
          . “
          <article-title>SMT-based false positive elimination in static program analysis</article-title>
          ,
          <source>” Proceedings of 14th International Conference on Formal Engineering Methods</source>
          , Japan, Volume
          <volume>7635</volume>
          <source>of LNCS</source>
          . Springer, pp.
          <fpage>316</fpage>
          -
          <lpage>331</lpage>
          ,
          <year>November 2012</year>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          - 34281-3_
          <fpage>23</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>W.</given-names>
            <surname>Choi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Chandra</surname>
          </string-name>
          , G. Necula,
          <string-name>
            <given-names>K.</given-names>
            <surname>Sen</surname>
          </string-name>
          .
          <article-title>"SJS: A Type System for JavaScript with Fixed Object Layout,"</article-title>
          <source>International Static Analysis Symposium, Static Analysis</source>
          , pp.
          <fpage>181</fpage>
          -
          <lpage>198</lpage>
          ,
          <year>September 2015</year>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>662</fpage>
          -48288-9_
          <fpage>11</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Luo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Rezk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Serrano</surname>
          </string-name>
          . “
          <article-title>Automated code injection prevention for web applications</article-title>
          ,
          <source>” Proceedings of the 2011 international conference on Theory of Security and Applications</source>
          , pp.
          <fpage>186</fpage>
          -
          <lpage>204</lpage>
          ,
          <year>March 2011</year>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -27375-9_
          <fpage>11</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>D.</given-names>
            <surname>Ray</surname>
          </string-name>
          ,
          <string-name>
            <surname>J. Ligatti. “</surname>
          </string-name>
          <article-title>Defining code-injection attacks,” Proceeding of the 39th annual ACM SIGPLAN-SIGACT symposium on Principles of programming languages</article-title>
          , pp.
          <fpage>179</fpage>
          -
          <lpage>190</lpage>
          ,
          <year>January 2012</year>
          . DOI:
          <volume>10</volume>
          .1145/2103656.2103678.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>S.</given-names>
            <surname>Seo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Gupta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sallam</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Bertino</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Yim</surname>
          </string-name>
          . “
          <article-title>Detecting mobile malware threats to homeland security through static analysis</article-title>
          ,
          <source>” Journal of Network and Computer Applications</source>
          , vol:
          <volume>38</volume>
          (
          <issue>1</issue>
          ) pp.
          <fpage>43</fpage>
          -
          <lpage>53</lpage>
          ,
          <year>February 2014</year>
          . DOI:
          <volume>10</volume>
          .1016/j.jnca.
          <year>2013</year>
          .
          <volume>05</volume>
          .008.
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>W.</given-names>
            <surname>Lee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Oh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Yi</surname>
          </string-name>
          .
          <article-title>"A Progress Bar for Static Analyzers,"</article-title>
          <source>International Static Analysis Symposium, Static Analysis</source>
          , pp.
          <fpage>184</fpage>
          -
          <lpage>200</lpage>
          ,
          <year>September 2014</year>
          , DOI: 10.1007/978-3-
          <fpage>319</fpage>
          -10936-7_
          <fpage>12</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>E.</given-names>
            <surname>Goubault</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Putot</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Vedrine</surname>
          </string-name>
          .
          <article-title>"Modular static analysis with zonotopes,"</article-title>
          <source>International Static Analysis Symposium, Static Analysis</source>
          , pp.
          <fpage>24</fpage>
          -
          <lpage>40</lpage>
          ,
          <year>September 2012</year>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -33125-
          <issue>1</issue>
          _
          <fpage>5</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>P.</given-names>
            <surname>Calvert</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mycroft</surname>
          </string-name>
          .
          <article-title>"Control Flow Analysis for the Join Calculus,"</article-title>
          <source>International Static Analysis Symposium, Static Analysis</source>
          , pp.
          <fpage>181</fpage>
          -
          <lpage>197</lpage>
          ,
          <year>September 2012</year>
          . DOI 10.1007/978-3-
          <fpage>642</fpage>
          -33125-1_
          <fpage>14</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>M.</given-names>
            <surname>Madsen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Moller</surname>
          </string-name>
          .
          <article-title>"Sparse Dataflow Analysis with Pointers and Reachability,"</article-title>
          <source>International Static Analysis Symposium, Static Analysis</source>
          , pp.
          <fpage>201</fpage>
          -
          <lpage>218</lpage>
          ,
          <year>September 2014</year>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -10936-7_
          <fpage>13</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>A.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Fadin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Shvets</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Tsirlov</surname>
          </string-name>
          . “
          <article-title>The experience of comparison of static security code analyzers</article-title>
          ,”
          <source>International Journal of Advanced Studies</source>
          , vol.
          <volume>5</volume>
          . № 3. pp.
          <fpage>55</fpage>
          -
          <lpage>63</lpage>
          ,
          <year>September 2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>D.</given-names>
            <surname>Zhu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Jung</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Song</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Kohno</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.</surname>
          </string-name>
          <article-title>Wetherall “TaintEraser: protecting sensitive data leaks using application-level taint tracking,” Newsletter ACM SIGOPS Operating Systems Review archive</article-title>
          ,
          <year>January 2011</year>
          , Volume
          <volume>45</volume>
          , Issue 1, pp.
          <fpage>142</fpage>
          -
          <lpage>154</lpage>
          . DOI: 0.1145/1945023.1945039.
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>A.</given-names>
            <surname>Barabanov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Fadin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Tsirlov</surname>
          </string-name>
          . “
          <source>Statistics of Software Vulnerabilities Detection During Certified Testing,” Voprosy kiberbezopasnosti [Cybersecurity Issues]. No</source>
          <volume>2</volume>
          (
          <issue>20</issue>
          ), pp.
          <fpage>2</fpage>
          -
          <lpage>8</lpage>
          . May
          <year>2017</year>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2017-2
          <issue>-2</issue>
          -8.
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>A.</given-names>
            <surname>Barabanov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Fadin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Tsirlov</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Shakhalov.</surname>
          </string-name>
          “
          <source>Synthesis of Secure Software Development Controls,” The 8th International Conference on Security of Information and Networks (Sochi, Russian Federation, September 08-10</source>
          ,
          <year>2015</year>
          ).
          <source>SIN '15</source>
          . ACM New York, NY, USA, pp.
          <fpage>93</fpage>
          -
          <lpage>97</lpage>
          . September 08-
          <issue>10</issue>
          ,
          <year>2015</year>
          . DOI:
          <volume>10</volume>
          .1145/2799979.2799998.
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>A.V.</given-names>
            <surname>Barabanov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.S.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.L.</given-names>
            <surname>Tsirlov</surname>
          </string-name>
          . “
          <article-title>Methodological Framework for Analysis and Synthesis of a Set of Secure Software Development Controls</article-title>
          ,
          <source>” Journal of Theoretical and Applied Information Technology. V. 88. No 1</source>
          , pp.
          <fpage>77</fpage>
          -
          <lpage>88</lpage>
          ,
          <year>June 2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [33]
          <string-name>
            <given-names>A.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Barabanov</surname>
          </string-name>
          , V. Tsirlov V.
          <article-title>Models for Testing Modifiable Systems</article-title>
          . In Book:
          <article-title>Probabilistic Modeling in System Engineering</article-title>
          , by ed.
          <source>Andrey Kostogryzov. InTech</source>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>