Advanced Search

Content Type

Topics

Publication Date

Source Code Analysis Laboratory (SCALe)

Abstract

The Source Code Analysis Laboratory (SCALe) is a proof-of-concept demonstration that software systems can be conformance tested against secure coding standards. CERT® secure coding standards provide a detailed enumeration of coding errors that have resulted in vulnerabilities for commonly used software development languages. The SCALe team at the CERT Program, part of Carnegie Mellon University’s Software Engineering Institute, analyzes a developer’s source code and provides a detailed report of findings to guide the code’s repair. After the developer has addressed these findings and the SCALe team determines that the product version conforms to the standard, the CERT Program issues the developer a certificate and lists the system in a registry of conforming systems. This report details the SCALe process and provides an analysis of selected software systems.

Cite This Report

Show Citation Formats

SEI

Seacord, Robert; Dormann, Will; McCurley, James; Miller, Philip; Stoddard, Robert; Svoboda, David; & Welch, Jefferson. Source Code Analysis Laboratory (SCALe) (CMU/SEI-2012-TN-013). Software Engineering Institute, Carnegie Mellon University, 2012. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=10091

IEEE

Seacord. Robert, Dormann. Will, McCurley. James, Miller. Philip, Stoddard. Robert, Svoboda. David, and Welch. Jefferson, "Source Code Analysis Laboratory (SCALe)," Software Engineering Institute, Carnegie Mellon University, Pittsburgh, Pennsylvania, Technical Note CMU/SEI-2012-TN-013, 2012. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=10091

APA

Seacord, Robert., Dormann, Will., McCurley, James., Miller, Philip., Stoddard, Robert., Svoboda, David., & Welch, Jefferson. (2012). Source Code Analysis Laboratory (SCALe) (CMU/SEI-2012-TN-013). Retrieved October 20, 2014, from the Software Engineering Institute, Carnegie Mellon University website: http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=10091

CHI

Robert Seacord, Will Dormann, James McCurley, Philip Miller, Robert Stoddard, David Svoboda, & Jefferson Welch. Source Code Analysis Laboratory (SCALe) (CMU/SEI-2012-TN-013). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2012. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=10091

MLA

Seacord, Robert., Dormann, Will., McCurley, James., Miller, Philip., Stoddard, Robert., Svoboda, David., & Welch, Jefferson. 2012. Source Code Analysis Laboratory (SCALe) (Technical Report CMU/SEI-2012-TN-013). Pittsburgh: Software Engineering Institute, Carnegie Mellon University. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=10091