Software Engineering Institute (SEI) Podcast Series

Using Test Suites for Static Analysis Alert Classifiers

02.18.2019 - By Members of Technical Staff at the Software Engineering InstitutePlay

Download our free app to listen on your phone

Download on the App StoreGet it on Google Play

Static analysis tools used to identify potential vulnerabilities in source code produce a large number of alerts with high false-positive rates that engineers must painstakingly examine to find legitimate flaws. Researchers in the SEI’s CERT Division have developed the SCALe (Source Code Analysis Laboratory) tool to help analysts be more efficient and effective at auditing static analysis alerts. In this podcast, CERT researchers Lori Flynn and Zach Kurtz discuss ongoing research using test suites as a source of labeled training data to create classifiers for static analysis alerts.

More episodes from Software Engineering Institute (SEI) Podcast Series