Comparing Detection Ratio of Three Static Analysis Tools

  • Kaur H
  • Jai P
N/ACitations
Citations of this article
6Readers
Mendeley users who have this article in their library.

Abstract

Static code analysis is a software verification activity in which source code is scrutinized for quality and security. In a Software Development Lifecycle, timely detection of flaws is beneficial and static analysis tools help us to detect flaws at a very early stage. Both commercial and open source static analysis tools are available today. Due to diverse user requirements and capabilities of the tools, a comparison between tools is required. Three open source static analysis tools for security are evaluated in this paper. These are Cppcheck, RATS and Flawfinder. They have been studied and compared to each other on the basis of detection ratio. For the purpose of obtaining the detection ratio, the vulnerabilities were categorized and intentionally introduced into the demo codes. General Terms Security.

Cite

CITATION STYLE

APA

Kaur, H., & Jai, P. (2015). Comparing Detection Ratio of Three Static Analysis Tools. International Journal of Computer Applications, 124(13), 35–40. https://doi.org/10.5120/ijca2015905749

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free