
Sign up to save your podcasts
Or


Static analysis tools used to identify potential vulnerabilities in source code produce a large number of alerts with high false-positive rates that engineers must painstakingly examine to find legitimate flaws. Researchers in the SEI's CERT Division have developed the SCALe (Source Code Analysis Laboratory) tool to help analysts be more efficient and effective at auditing static analysis alerts. In this podcast, CERT researchers Lori Flynn and Zach Kurtz discuss ongoing research using test suites as a source of labeled training data to create classifiers for static analysis alerts.
By Members of Technical Staff at the Software Engineering Institute4.5
1818 ratings
Static analysis tools used to identify potential vulnerabilities in source code produce a large number of alerts with high false-positive rates that engineers must painstakingly examine to find legitimate flaws. Researchers in the SEI's CERT Division have developed the SCALe (Source Code Analysis Laboratory) tool to help analysts be more efficient and effective at auditing static analysis alerts. In this podcast, CERT researchers Lori Flynn and Zach Kurtz discuss ongoing research using test suites as a source of labeled training data to create classifiers for static analysis alerts.

32,246 Listeners

273 Listeners

26,380 Listeners

1,105 Listeners

626 Listeners

371 Listeners

651 Listeners

44 Listeners

317 Listeners

8,077 Listeners

73 Listeners

0 Listeners

0 Listeners

6,097 Listeners

1,348 Listeners

139 Listeners

16,525 Listeners