• DocumentCode
    3069462
  • Title

    Comparison of Static Code Analysis Tools

  • Author

    Mantere, Matti ; Uusitalo, Ilkka ; Röning, Juha

  • Author_Institution
    VTT Tech. Res. Centre of Finland, Oulu, Finland
  • fYear
    2009
  • fDate
    18-23 June 2009
  • Firstpage
    15
  • Lastpage
    22
  • Abstract
    In this paper we compare three static code analysis tools. The tools represent three different approaches in the field of static analysis: fortify SCA is a non-annotation based heuristic analyzer, Splint represents an annotation based heuristic analyzer, and Frama-C an annotation based correct analyzer. The tools are compared by analysing their performance when checking a demonstration code with intentionally implemented errors.
  • Keywords
    program diagnostics; security of data; software quality; software tools; Frama-C; information security; nonannotation based heuristic analyzer; software quality; static code analysis tools; Application software; Computer bugs; Computer errors; Failure analysis; Humans; Information analysis; Information security; Open source software; Performance analysis; Software quality;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Emerging Security Information, Systems and Technologies, 2009. SECURWARE '09. Third International Conference on
  • Conference_Location
    Athens, Glyfada
  • Print_ISBN
    978-0-7695-3668-2
  • Type

    conf

  • DOI
    10.1109/SECURWARE.2009.10
  • Filename
    5211037