icon-carat-right menu search cmu-wordmark

Collection of Static Analysis Assets

Collection
This collection contains materials on SEI’s research regarding how to improve alert systems in static analysis tools as well as the automation of these tools.
Publisher

Software Engineering Institute

Topic or Tag

Abstract

Static analysis (SA) tools analyze source code for security defects and alert users to issues that require repair. While invaluable, SA tools tend to produce a large number of alerts (many of which are false positives), making it difficult to identify valid alerts and, in turn, to address critical security defects. SEI researchers are actively publishing research and building prototype tools to improve static analysis alerts.

Collection Items