发明名称 Eliminating false-positive reports resulting from static analysis of computer software
摘要 A system for eliminating false-positive reports resulting from static analysis of computer software is provided herein. The system includes the following components executed by a processor: a modeler configured to model a computer code into a model that defines sources, sinks, and flows; a static analyzer configured to apply static analysis to the code or the model, to yield reports indicative of at least one issue relating to one or more of the flows; a preconditions generator configured to generate preconditions for eliminating false-positive issues in the reports, based on the model and user-provided input; and a preconditions checker configured to apply the generated preconditions to the reports for eliminating false-positive issues in the reports.
申请公布号 US8745578(B2) 申请公布日期 2014.06.03
申请号 US201113252229 申请日期 2011.12.04
申请人 International Business Machines Corporation 发明人 Pistoia Marco;Tripp Omer
分类号 G06F9/44;G06F9/45 主分类号 G06F9/44
代理机构 代理人
主权项 1. A method comprising: modeling a computer code into a model that defines sources, sinks, and flows; applying static analysis to the code or the model, to yield reports indicative of at least one issue relating to one or more of the flows; generating preconditions for eliminating false-positive issues in the reports reports, based on the model and user-provided input; and applying the generated preconditions to the reports for eliminating false-positive issues in the reports, wherein at least one of the modeling, the applying, and the generating is executed by at least one computer processor.
地址 Armonk NY US