Software Security Static Analysis False Alerts Handling Approaches

3Citations
Citations of this article
10Readers
Mendeley users who have this article in their library.

Abstract

False Positive Alerts (FPA), generated by Static Analyzers Tools (SAT), reduce the effectiveness of the automatic code review, letting them be underused in practice. Researchers conduct a lot of tests to improve SAT accuracy while keeping FPA at a lower rate. They use different simulated and production datasets to validate their proposed methods. This paper surveys recent approaches dealing with FPA filtering; it compares them and discusses their usefulness. It also studies the used datasets to validate the identified methods and show their effectiveness to cover most program defects. This study focuses mainly on the security bugs covered by the datasets and handled by the existing methods.

Cite

CITATION STYLE

APA

Akremi, A. (2021). Software Security Static Analysis False Alerts Handling Approaches. International Journal of Advanced Computer Science and Applications, 12(11), 702–711. https://doi.org/10.14569/IJACSA.2021.0121180

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free