False Positive Alerts (FPA), generated by Static Analyzers Tools (SAT), reduce the effectiveness of the automatic code review, letting them be underused in practice. Researchers conduct a lot of tests to improve SAT accuracy while keeping FPA at a lower rate. They use different simulated and production datasets to validate their proposed methods. This paper surveys recent approaches dealing with FPA filtering; it compares them and discusses their usefulness. It also studies the used datasets to validate the identified methods and show their effectiveness to cover most program defects. This study focuses mainly on the security bugs covered by the datasets and handled by the existing methods.
CITATION STYLE
Akremi, A. (2021). Software Security Static Analysis False Alerts Handling Approaches. International Journal of Advanced Computer Science and Applications, 12(11), 702–711. https://doi.org/10.14569/IJACSA.2021.0121180
Mendeley helps you to discover research relevant for your work.