Close Menu
BlogSpotTipsBlogSpotTips
  • Home
  • Education
  • Finance
  • Latest Internet News
    • Social Media
    • Software
  • Game
  • Contact Us !
Facebook X (Twitter) Instagram
BlogSpotTipsBlogSpotTips
  • Home
  • Education
  • Finance
  • Latest Internet News
    • Social Media
    • Software
  • Game
  • Contact Us !
Facebook X (Twitter) Instagram
BlogSpotTipsBlogSpotTips
Home»Software»NIST tool boosts chances of finding dangerous software flaws
Software

NIST tool boosts chances of finding dangerous software flaws

Loknath DasBy Loknath DasApril 29, 2019No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

After more than 20 years of steady improvement, the US National Institute of Standards and Technology (NIST) thinks it has reached an important milestone with something called Combinatorial Coverage Measurement (CCM).

Part of a research toolkit called Automated Combinatorial Testing for Software (ACTS), CCM is an algorithmic approach used to test software for interactions between input variables that might cause unexpected failures.

It sounds like a technical mouthful, but this is good news for software, especially when it’s inside complex systems such as aircraft, cars and power plants where these sorts of problems could be life-threatening.

Typically, this will be software taking inputs from arrays of sensors that generate unexpected conflicts the software can’t resolve, for instance between temperature, pressure or altitude.

Designers try to counteract these problems by modelling as many interactions as they can before the software is used in the real world, which is where ACTS and CCM come in.

But there’s always been a problem – modelling enough interactions from enough variables to spot all the possible combinations that might lead to an issue.

This has been improving since the late 1990s when the idea got off the ground, most recently during a revision to the ACTS toolkit in 2015.

Now, in collaboration with University of Texas, Austria’s SBA Research, and Adobe (one of several big companies using the toolkit), NIST thinks that the 2019 revision of CCM has made some kind of leap forward.

NIST mathematician Raghu Kacker said of the difficulties of testing complex software:

Before we revised CCM, it was difficult to test software that handled thousands of variables thoroughly. That limitation is a problem for complex modern software of the sort that is used in passenger airliners and nuclear power plants, because it’s not just highly configurable, it’s also life critical. People’s lives and health are depending on it.

With the help of a new algorithm developed by SBA, NIST’s tool had gone from being able to model a few hundred variables to up to 2,000 from five-way combinations of inputs.

Although not an official part of the tool, developers could request the algorithm. NIST computer scientist Richard Kuhn said:

The collaboration has shown that we can handle larger classes of problems now. We can apply this method to more applications and systems that previously were too hard to handle.

Not far from the surface of this development is the problem of cost – how much time and effort should developers spend removing bugs from their software?

NIST’s hope must be that anything that can remove more bugs for the same effort is going to have a positive effect on security and reliability.

Unfortunately, as helpful as CCM might be, its effectiveness must now be measured against the rising complexity of software systems that are acquiring once unimagined capabilities, such as automation.

There is an expanding range of commercial products that want to help solve this problem. The investment NIST is making in ACTS and CCM suggests there is still plenty of room for a toolset that everyone can use.

[“source=nakedsecurity.sophos”]

boosts chances dangerous finding flaws NIST of software tool
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Loknath Das

Related Posts

How to Avoid Managing Open Source Software’s

March 24, 2025

Strategies for Structuring and Scaling High-performance Data Labeling Teams

March 12, 2025

Release Your Business Potential in Patna with Custom Programming Advancement Arrangements

February 1, 2025
Recent Post
  • How to Grow Your Brand with Micro Influencer Marketing
  • What Are the 8 Different Types of Video Game Articles?
  • Strategies for Greater Financial Flexibility: 5 Smart Ways to Repay Your Home Loan Faster
  • PS5 Pro vs the PS5 – What’s the difference, really?
  • 4 Tips to Improve Data Loss Prevention (DLP) in Healthcare
  • A+ methods: Help students get ready for state exams
  • Again, winter greetings
  • Living games are here: How gen AI is leveling up the games industry
Search
  • Home
  • Privacy Policy
  • Contact Us !
© 2025 BlogSpotTips. Designed by BlogSpotTips.

Type above and press Enter to search. Press Esc to cancel.