2017
DOI: 10.6028/nist.ir.8165
|View full text |Cite
|
Sign up to set email alerts
|

Impact of code complexity on software analysis

Abstract: The Software Assurance Metrics and Tool Evaluation (SAMATE) team studied thousands of warnings from static analyzers. Tools have difficulty distinguishing between the absence of a weakness and the presence of a weakness that is buried in otherwise-irrelevant code elements. This paper presents classes of these code elements, which we call "code complexities."They have been present in software assurance as part of test cases generation strategy when evaluating static analyzers. Benefits of using code complexity … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2018
2018
2018
2018

Publication Types

Select...
1

Relationship

1
0

Authors

Journals

citations
Cited by 1 publication
(1 citation statement)
references
References 11 publications
0
1
0
Order By: Relevance
“…The Intelligence Advanced Research Projects Activity (IARPA) attempted to combine all three properties of an ideal test suite in its Securely Taking On New Executable Software of Uncertain Provenance STONESOUP program [25,26]. IARPA created 7770 test cases by injecting small code snippets, containing weaknesses, into sixteen open source base programs.…”
Section: Related Workmentioning
confidence: 99%
“…The Intelligence Advanced Research Projects Activity (IARPA) attempted to combine all three properties of an ideal test suite in its Securely Taking On New Executable Software of Uncertain Provenance STONESOUP program [25,26]. IARPA created 7770 test cases by injecting small code snippets, containing weaknesses, into sixteen open source base programs.…”
Section: Related Workmentioning
confidence: 99%