Source Code Analysis Laboratory (SCALe)

The Source Code Analysis Laboratory (SCALe) is a proof-of-concept demonstration that software systems can be conformance tested against secure coding standards. CERT® secure coding standards provide a detailed enumeration of coding errors that have resulted in vulnerabilities for commonly used software development languages. The SCALe team at the CERT Program, part of Carnegie Mellon University's Software Engineering Institute, analyzes a developer's source code and provides a detailed report of findings to guide the code's repair. After the developer has addressed these findings and the SCALe team determines that the product version conforms to the standard, the CERT Program issues the developer a certificate and lists the system in a registry of conforming systems. This report details the SCALe process and provides an analysis of selected software systems.

PDF [560 KB]

Authors

Robert C. Seacord

Will Dormann

James McCurley

Philip Miller

Robert W. Stoddard

David Svoboda

Jefferson Welch

This report is related to the following area(s) of work:

Security and Survivability

Technical Note
CMU/SEI-2012-TN-013
April 2012

Cite This Report

SEI:

Seacord, Robert; Dormann, Will; McCurley, James; Miller, Philip; Stoddard, Robert; Svoboda, David; & Welch, Jefferson. Source Code Analysis Laboratory (SCALe) (CMU/SEI-2012-TN-013). Software Engineering Institute, Carnegie Mellon University, 2012. http://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm

IEEE:

R. Seacord, W. Dormann, J. McCurley, P. Miller, R. Stoddard, D. Svoboda, and J. Welch, "Source Code Analysis Laboratory (SCALe)," Software Engineering Institute, Carnegie Mellon University, Pittsburgh, Pennsylvania, Technical Note CMU/SEI-2012-TN-013, 2012. http://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm

APA:

Seacord, R., Dormann, W., McCurley, J., Miller, P., Stoddard, R., Svoboda, D., & Welch, J. (2012). Source Code Analysis Laboratory (SCALe) (CMU/SEI-2012-TN-013). Retrieved May 25, 2013, from the Software Engineering Institute, Carnegie Mellon University website: http://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm

CHI:

Seacord, Robert, Will Dormann, James McCurley, Philip Miller, Robert Stoddard, David Svoboda, and Jefferson Welch. Source Code Analysis Laboratory (SCALe) (CMU/SEI-2012-TN-013). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2012. http://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm

MLA:

Seacord, R., Dormann, W., McCurley, J., Miller, P., Stoddard, R., Svoboda, D., & Welch, J. 2012. Source Code Analysis Laboratory (SCALe) (Technical Report CMU/SEI-2012-TN-013). Pittsburgh: Software Engineering Institute, Carnegie Mellon University. http://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm

Find Us Here

Find us on Youtube  Find us on LinkedIn  Find us on twitter  Find us on Facebook

Share This Page

Share on Facebook  Send to your Twitter page  Save to del.ico.us  Save to LinkedIn  Digg this  Stumble this page.  Add to Technorati favorites  Save this page on your Google Home Page 

For more information

Contact Us

info@sei.cmu.edu

412-268-5800

Help us improve

Visitor feedback helps us continually improve our site.

Please tell us what you
think with this short
(< 5 minute) survey.