Computer security has experienced important fundamental changes over the past decade. The most promising developments in security involve arming software developers and architects with the knowledge and tools they need to build more secure software. Among the many security tools available to software practitioners, static analysis tools for automated code review are the most effective. The paper presents how they work and why all developers should use them.
No takes yet. Share an insight, caveat, or question.
Gary McGraw (2008) studied this question.
Synapse has enriched one closely related paper. Consider it for comparative context: