A Practical Approach for Ranking Software Warnings from Multiple Static Code Analysis Reports

Binh Hy Dang · 2020

Static analysis tools examine source code to look for software flaws and potential vulnerabilities. It is a common practice to use multiple tools so that we do not overlook code which truly has a problem. However, the problem of using multiple bugs finding tools is they not only detect similar software defects but also generate new warning messages. The excessive warnings make code analysis time consuming and expensive. In this paper, we describe our methods to merge software warning categories from different bugs finding tools from two popular programming languages such as Java and C++, and prioritize the files consolidated warning messages by building an analytical model using principal component analysis. Results have shown that files real software defects occupied top of the list, and false positives occupied the bottom slots.

Read the paper · More papers on PaperTik