Effect of static analysis tools on software security: preliminary investigation

  • Authors:
  • Vadim Okun;William F. Guthrie;Romain Gaucher;Paul E. Black

  • Affiliations:
  • National Institute of Standards and Technology, Gaithersburg, MD;National Institute of Standards and Technology, Gaithersburg, MD;National Institute of Standards and Technology, Gaithersburg, MD;National Institute of Standards and Technology, Gaithersburg, MD

  • Venue:
  • Proceedings of the 2007 ACM workshop on Quality of protection
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Static analysis tools can handle large-scale software and find thousands of defects. But do they improve software security? We evaluate the effect of static analysis tool use on software security in open source projects. We measure security by vulnerability reports in the National Vulnerability Database.