Static Code Analysis for Automotive Software
Dennis Kengo Oka · 2021
Static code analysis is typically used as part of improving software security during the development phase. This chapter covers two main topics related to static code analysis. First, static code analysis can be used to detect weakness patterns and vulnerabilities in the software early during development. Second, static code analysis can be used to check the code for compliance to various coding guidelines such as Computer Emergency Response Team, MISRA (Motor Industry Software Reliability Association), and AUTOSAR (AUTomotive Open System ARchitecture) coding guidelines. Considering especially safety and security implications in automotive systems, there may be requirements for the software of an automotive system to be compliant with MISRA or AUTOSAR coding guidelines. However, the automotive system in question may be a complex system containing several layers of different software including own-developed code, third-party developed code, commercial software, and open-source software.