Qualitative and Quantitative Evaluation of Static Code Analysis Tools

dc.contributor.authorVelicheti, Lakshmi Manohar Rao
dc.contributor.authorFeiock, Dennis C.
dc.contributor.authorRaje, Rajeev R.
dc.contributor.authorHill, James H.
dc.date.accessioned2015-09-03T16:23:49Z
dc.date.available2015-09-03T16:23:49Z
dc.date.issued2013-04-05
dc.descriptionposter abstracten_US
dc.description.abstractStatic code analysis (SCA) is a methodology of detecting errors in programs without actually compiling the source code to binary format and executing it on a machine. The main goal of a SCA tool is to aid developers in quickly identifying errors that can jeopardize the security and integrity of the program. With the vast array of SCA tools available, each specializing in particular languages, error types, and detection methodologies, choosing the optimal tool(s) can be a daunting task for any software developer, or organization. This, however, is not a problem associated only with SCA tools, but applies to any application domain where many tools exist and a selection of a subset of these tools is needed for effectively tackling a given problem. To address this fundamental challenge with selecting the most appropriate SCA tool for a particular problem, this research is performing a comprehensive study of different available SCA tool, both commercial and open-source. The end goal of this study is to not only evaluate how different SCA tools perform with respect to locating specific errors in source code (i.e., the quality of the tool), but to model the behavior of each SCA tool using quantitative metrics gathered from the source code, such as source lines of code (SLOC), cyclometic complexity, and function points. The behavioral model can then be used to prescreen existing (and new) source code, and select the most appropriate SCA tool, or set of SCA tools, that can identify the most errors in the source code undergoing analysis.en_US
dc.identifier.citationVelicheti, Lakshmi Manohar Rao, Dennis C. Feiock, Rajeev R. Raje, and James H. Hill. (2013, April 5). Qualitative and Quantitative Evaluation of Static Code Analysis Tools. Poster session presented at IUPUI Research Day 2013, Indianapolis, Indiana.en_US
dc.identifier.urihttps://hdl.handle.net/1805/6717
dc.language.isoen_USen_US
dc.publisherOffice of the Vice Chancellor for Researchen_US
dc.subjectstatic code analysis (SCA)en_US
dc.subjectsource codeen_US
dc.subjectsource lines of code (SLOC)en_US
dc.subjectcyclometric complexityen_US
dc.subjectfunction pointsen_US
dc.titleQualitative and Quantitative Evaluation of Static Code Analysis Toolsen_US
dc.typePresentationen_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Velicheti-qualitative.pdf
Size:
58.89 KB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.88 KB
Format:
Item-specific license agreed upon to submission
Description: