3 min

Automating Alert Handling Reduces Manual Effort SEI Shorts

    • Technology

Static analysis (SA) alerts about software code flaws require costly manual effort to validate (e.g., determine True or False) and repair.  As a result, organizations often severely limit the types of alerts they manually examine to the types of code flaws they most worry about. That approach results in a tradeoff where many True flaws may never get fixed. To make alert handling more efficient, the SEI developed and tested novel software that enables the rapid deployment of a method to classify alerts automatically and accurately. We are implementing our solution in a new version of the SEI’s SCALe – the Source Code Analysis Lab – application.

Static analysis (SA) alerts about software code flaws require costly manual effort to validate (e.g., determine True or False) and repair.  As a result, organizations often severely limit the types of alerts they manually examine to the types of code flaws they most worry about. That approach results in a tradeoff where many True flaws may never get fixed. To make alert handling more efficient, the SEI developed and tested novel software that enables the rapid deployment of a method to classify alerts automatically and accurately. We are implementing our solution in a new version of the SEI’s SCALe – the Source Code Analysis Lab – application.

3 min

Top Podcasts In Technology

Lex Fridman Podcast
Lex Fridman
3 στον αέρα
Insomnia.gr
Μικρή Κουβέντα
Μικρή Κουβέντα
Waveform: The MKBHD Podcast
Vox Media Podcast Network
Malicious Life
Malicious Life
Acquired
Ben Gilbert and David Rosenthal

More by Carnegie Mellon University

SEI Cyber Talks
Members of Technical Staff
SEI Shorts
Members of Technical Staff at the Software Engineering Institute
Make It Real
CMU Engineering
Software Engineering Institute (SEI) Webcast Series
SEI Members of Technical Staff
Software Engineering Institute (SEI) Podcast Series
Members of Technical Staff at the Software Engineering Institute