METHOD FOR THE ANALYSIS OF SOURCE TEXTS
A method for the analysis of source texts comprises identifying source text vulnerabilities that are susceptible to implementation attacks, wherein the identification of the source text vulnerabilities takes place during active source text development, without the need to compile the program.
1 . A method for the analysis of source texts comprising:
identifying source text vulnerabilities in the program that are susceptible to implementation attacks, wherein the identifying occurs during active source text development without the need to compile the program.
2 . The method as claimed in claim 1 , further comprising:
identifying source text vulnerabilities that are susceptible to side-channel attacks; and
identifying source text vulnerabilities that are susceptible to fault injection attacks.
3 . The method as claimed in claim 1 , further comprising visually highlighting the identified source text vulnerabilities, wherein the visual highlighting takes place during active source text development without the need to compile the program.
4 . The method as claimed in claim 1 , wherein at least one of the identifying and the visual highlighting takes place in real time during active source text development.
5 . The method as claimed in claim 1 , further comprising at least one of:
automatic loading of a stored explanation regarding an identified source text vulnerability;
automatic generation of an explanation regarding an identified source text vulnerability; and
automatic display of the loaded or generated explanation of the identified source text vulnerability.
6 . The method as claimed in claim 1 , further comprising at least one of:
automatic generation of an alternative source text for an identified source text vulnerability; and
automatic display of the generated source text alternative to the identified source text vulnerability.
7 . The method as claimed in claim 6 , further comprising automatic replacement of the identified source text vulnerability by the generated alternative source text on the basis of a correction command entered by a source text developer.
8 . A device for data processing comprising:
a processor that is configured with instructions for identifying source text vulnerabilities in the program that are susceptible to implementation attacks, wherein the identifying occurs during active source text development without the need to compile the program.
9 . The device as claimed in claim 8 , wherein the processor further comprises instructions for:
identifying source text vulnerabilities that are susceptible to side-channel attacks; and
identifying source text vulnerabilities that are susceptible to fault injection attacks.
10 . The device as claimed in claim 8 , wherein the processor further comprises instructions for visually highlighting the identified source text vulnerabilities, wherein the visual highlighting takes place during active source text development without the need to compile the program.
11 . The device as claimed in claim 8 , wherein at least one of the identifying and the visual highlighting takes place in real time during active source text development.
12 . The device as claimed in claim 8 , wherein the processor further comprises instructions for at least one of:
automatic loading of a stored explanation regarding an identified source text vulnerability;
automatic generation of an explanation regarding an identified source text vulnerability; and
automatic display of the loaded or generated explanation of the identified source text vulnerability.
13 . The device as claimed in claim 8 , wherein the processor further comprises instructions for at least one of:
automatic generation of an alternative source text for an identified source text vulnerability; and
automatic display of the generated source text alternative to the identified source text vulnerability.
14 . The device as claimed in claim 13 , wherein the processor further comprises instructions for automatic replacement of the identified source text vulnerability by the generated alternative source text on the basis of a correction command entered by a source text developer.
15 . A computer program product comprising commands which, when the program is carried out by a computer, cause identifying source text vulnerabilities in the program that are susceptible to implementation attacks, wherein the identifying occurs during active source text development without the need to compile the program.
16 . The computer program product of claim 15 , wherein computer program product is stored on a computer-readable data carrier.