search menu icon-carat-right cmu-wordmark

Source Code Analysis Laboratory (SCALe) for Energy Delivery Systems

Technical Report
In this report, the authors describe the Source Code Analysis Laboratory (SCALe), which tests software for conformance to CERT secure coding standards.
Publisher

Software Engineering Institute

CMU/SEI Report Number
CMU/SEI-2010-TR-021

Abstract

The Source Code Analysis Laboratory (SCALe) is an operational capability that tests software applications for conformance to one of the CERT secure coding standards. CERT secure coding standards provide a detailed enumeration of coding errors that have resulted in vulnerabilities for commonly used software development languages. The SCALe team at CERT, a program of Carnegie Mellon University’s Software Engineering Institute, analyzes a developer’s source code and provides a detailed report of findings to guide the code’s repair. After the developer has addressed these findings and the SCALe team determines that the product version conforms to the standard, CERT issues the developer a certificate and lists the system in a registry of conforming systems. This report details the SCALe process and provides an analysis of energy delivery systems. Though SCALe can be used in various capacities, it is particularly significant for conformance testing of energy delivery systems because of their critical importance.

Part of a Collection

SCALe Collection

Cite This Technical Report

Seacord, R., Dormann, W., McCurley, J., Miller, P., Stoddard, R., Svoboda, D., & Welch, J. (2010, December 1). Source Code Analysis Laboratory (SCALe) for Energy Delivery Systems. (Technical Report CMU/SEI-2010-TR-021). Retrieved April 18, 2024, from https://insights.sei.cmu.edu/library/source-code-analysis-laboratory-scale-for-energy-delivery-systems/.

@techreport{seacord_2010,
author={Seacord, Robert and Dormann, William and McCurley, Jim and Miller, Philip and Stoddard, Robert and Svoboda, David and Welch, Jefferson},
title={Source Code Analysis Laboratory (SCALe) for Energy Delivery Systems},
month={Dec},
year={2010},
number={CMU/SEI-2010-TR-021},
howpublished={Carnegie Mellon University, Software Engineering Institute's Digital Library},
url={https://insights.sei.cmu.edu/library/source-code-analysis-laboratory-scale-for-energy-delivery-systems/},
note={Accessed: 2024-Apr-18}
}

Seacord, Robert, William Dormann, Jim McCurley, Philip Miller, Robert Stoddard, David Svoboda, and Jefferson Welch. "Source Code Analysis Laboratory (SCALe) for Energy Delivery Systems." (CMU/SEI-2010-TR-021). Carnegie Mellon University, Software Engineering Institute's Digital Library. Software Engineering Institute, December 1, 2010. https://insights.sei.cmu.edu/library/source-code-analysis-laboratory-scale-for-energy-delivery-systems/.

R. Seacord, W. Dormann, J. McCurley, P. Miller, R. Stoddard, D. Svoboda, and J. Welch, "Source Code Analysis Laboratory (SCALe) for Energy Delivery Systems," Carnegie Mellon University, Software Engineering Institute's Digital Library. Software Engineering Institute, Technical Report CMU/SEI-2010-TR-021, 1-Dec-2010 [Online]. Available: https://insights.sei.cmu.edu/library/source-code-analysis-laboratory-scale-for-energy-delivery-systems/. [Accessed: 18-Apr-2024].

Seacord, Robert, William Dormann, Jim McCurley, Philip Miller, Robert Stoddard, David Svoboda, and Jefferson Welch. "Source Code Analysis Laboratory (SCALe) for Energy Delivery Systems." (Technical Report CMU/SEI-2010-TR-021). Carnegie Mellon University, Software Engineering Institute's Digital Library, Software Engineering Institute, 1 Dec. 2010. https://insights.sei.cmu.edu/library/source-code-analysis-laboratory-scale-for-energy-delivery-systems/. Accessed 18 Apr. 2024.

Seacord, Robert; Dormann, William; McCurley, Jim; Miller, Philip; Stoddard, Robert; Svoboda, David; & Welch, Jefferson. Source Code Analysis Laboratory (SCALe) for Energy Delivery Systems. CMU/SEI-2010-TR-021. Software Engineering Institute. 2010. https://insights.sei.cmu.edu/library/source-code-analysis-laboratory-scale-for-energy-delivery-systems/