Accession Number:

ADA610467

Title:

Source Code Analysis Laboratory (SCALe)

Descriptive Note:

Final rept.

Corporate Author:

CARNEGIE-MELLON UNIV PITTSBURGH PA SOFTWARE ENGINEERING INST

Report Date:

2012-04-01

Pagination or Media Count:

55.0

Abstract:

The Source Code Analysis Laboratory SCALe is a proof-of-concept demonstration that software systems can be conformance tested against secure coding standards. CERT secure coding standards provide a detailed enumeration of coding errors that have resulted in vulnerabilities for commonly used software development languages. The SCALe team at the CERT Program, part of Carnegie Mellon Universitys Software Engineering Institute, analyzes a developers source code and provides a detailed report of findings to guide the codes repair. After the developer has addressed these findings and the SCALe team determines that the product version conforms to the standard, the CERT Program issues the developer a certificate and lists the system in a registry of conforming systems. This report details the SCALe process and provides an analysis of selected software systems.

Subject Categories:

  • Computer Programming and Software
  • Safety Engineering

Distribution Statement:

APPROVED FOR PUBLIC RELEASE