Le Lézard
Classified in: Science and technology
Subject: PDT

SEI CERT Division Releases Downloadable Source Code Analysis Tool


PITTSBURGH, Aug. 15, 2018 /PRNewswire/ -- The CERT Division of the Software Engineering Institute (SEI) at Carnegie Mellon University today announced the release of its Source Code Analysis Laboratory (SCALe) application. This is the first release of the SCALe application to the public via open-source.

Software Engineering Institute Carnegie Mellon University (PRNewsfoto/Software Engineering Institute)

SCALe can be used for auditing software in any source code language. This version of SCALe provides categories of alerts for tools based on two code flaw taxonomies?CERT Secure Coding Standards and MITRE's Common Weakness Enumeration (CWE). The CERT Secure Coding Standards support detailed guidance for secure development in C, C++, Java, and Perl.

The SCALe application can be used to identify source code flaws that may lead to vulnerabilities. By using output from multiple flaw-finding static analysis tools, SCALe can be used to efficiently analyze more code defects than any single static analysis tool would find.

"Using multiple static analysis tools can greatly increase the types of flaws found," said Lori Flynn, senior software security researcher at the SEI. "The alerts must be examined by an expert who determines whether each alert represents an actual code defect. Typically there are too many alerts, and not all can be manually examined. The SCALe system is designed to make this process easier. We are researching ways to automate the process of accurate alert classification and sophisticated methods of alert prioritization, and this version of SCALe includes features added over the last three years intended to assist with that." 

The SCALe application simplifies the process of auditing alerts. It takes as input the source code for a program, plus output from static analysis tools (flaw-finding tools and code metrics tools) that were run on the code. With this input, it provides a browser-based interface to the alerts and their associated code. It provides simple prioritizations of the alerts and relevant information about the potential vulnerabilities and how to fix the code based on the CERT Secure Coding Standards and CWEs. It makes auditor work more efficient by fusing alerts into a single view that requires only one audit determination.

SCALe provides an easy-to-use graphical user interface for examining alerts, identifying true positives and other determinations, and saving the audit information to a database. 

For more information about the SCALe application, see https://resources.sei.cmu.edu/library/asset-view.cfm?assetID=473847. Download the application at https://github.com/cmu-sei/SCALe.

About the Carnegie Mellon University Software Engineering Institute
The Software Engineering Institute (SEI) is a federally funded research and development center sponsored by the U.S. Department of Defense and operated by Carnegie Mellon University. The SEI works with organizations to make measurable improvements in their software engineering capabilities by providing technical leadership to advance the practice of software engineering. For more information, visit the SEI website at http://www.sei.cmu.edu. The CERT Division of the SEI is the world's leading trusted authority dedicated to improving the security and resilience of computer systems and networks and a national asset in the field of cybersecurity. For more information, visit http://www.cert.org.

SOURCE Carnegie Mellon Software Engineering Institute


These press releases may also interest you

at 20:16
Evolution Equity Partners announced the final closing of Evolution Technology Fund III, LP on April 16th, 2024, and total capital commitments of $ 1.1 Billion to back visionary entrepreneurs building next generation...

at 20:11
SessionGuardian, a leading provider of continuous identity assurance and data protection solutions, celebrates the addition of its newly appointed, exceptional advisors. The remarkable achievements and insights of these key industry leaders will...

at 19:22
SK hynix Inc. (or "the company", www.skhynix.com) announced today that it recorded 12.43 trillion won in revenues, 2.886 trillion won in operating...

at 19:02
Arizona Governor Katie Hobbs, Arizona Corporation Commission (ACC) Commissioner Lea Marquez Peterson, and executives from Arizona Public Service (APS), Longroad Energy (Longroad), McCarthy Building Companies (McCarthy), and U.S. Bancorp Impact...

at 19:00
Terra Drone Corporation, a leading drone and Advanced Air Mobility (AAM) technology provider headquartered in Japan, announced today the launch of joint development with its Group companies Unifly NV ("Unifly") and Aloft Technologies Inc. ("Aloft")...

at 19:00
Terra Drone Corporation, a leading drone and Advanced Air Mobility (AAM) technology provider headquartered in Japan, has announced the launch of joint development with its Group companies Unifly NV ("Unifly") and Aloft Technologies Inc. ("Aloft")...



News published on and distributed by: