<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SEI Blog | Static Analysis</title><link>http://sei.cmu.edu/feeds/tag/</link><description>Updates on changes and additions to the                         SEI Blog for posts matching Static Analysis</description><atom:link href="http://sei.cmu.edu/blog/feeds/tag/static-analysis/atom/" rel="self"/><language>en-us</language><lastBuildDate>Mon, 07 Oct 2024 00:00:00 -0400</lastBuildDate><item><title>Evaluating Static Analysis Alerts with LLMs</title><link>https://www.sei.cmu.edu/blog/evaluating-static-analysis-alerts-with-llms/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>LLMs show promising initial results in adjudicating static analysis alerts, offering possibilities for better vulnerability detection. This post discusses initial experiments using GPT-4 to evaluate static analysis alerts.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">William Klieber, Lori Flynn</dc:creator><pubDate>Mon, 07 Oct 2024 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/evaluating-static-analysis-alerts-with-llms/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Static Analysis</category><category>AI Engineering and Machine Learning</category><category>Secure Coding</category></item><item><title>Redemption: A Prototype for Automated Repair of Static Analysis Alerts</title><link>https://www.sei.cmu.edu/blog/redemption-a-prototype-for-automated-repair-of-static-analysis-alerts/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post introduces Redemption, an open source tool that uses automated code repair technology to repair static analysis alerts in C/C++ source code.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Svoboda</dc:creator><pubDate>Mon, 10 Jun 2024 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/redemption-a-prototype-for-automated-repair-of-static-analysis-alerts/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Static Analysis</category><category>Secure Coding</category><category>Testing</category></item><item><title>Release of SCAIFE System Version 2.0.0 Provides Support for Continuous-Integration (CI) Systems</title><link>https://www.sei.cmu.edu/blog/release-of-scaife-system-version-200-provides-support-for-continuous-integration-ci-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Key features in new release of SCAIFE System Version 2.0.0 including support for continuous-integration (CI) systems, and status of evolving SEI SCAIFE work</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lori Flynn</dc:creator><pubDate>Mon, 25 Oct 2021 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/release-of-scaife-system-version-200-provides-support-for-continuous-integration-ci-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Continuous Deployment of Capability</category><category>SCALE: A Static Analysis Auditing Tool</category><category>Secure Coding</category><category>Machine Learning</category><category>Static Analysis</category><category>Static Analysis Classification and Prioritization</category><category>Secure Development</category><category>Artificial Intelligence</category><category>Source Code Analysis Integrated Framework Environment (SCAIFE)</category></item><item><title>How to Use Static Analysis to Enforce SEI CERT Coding Standards for IoT Applications</title><link>https://www.sei.cmu.edu/blog/how-to-use-static-analysis-to-enforce-sei-cert-coding-standards-for-iot-applications/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>The Jeep hack, methods to hack ATMs, and even hacks to a casino's fish tank provide stark evidence of the risks associated with the Internet of Things (IoT)....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Svoboda</dc:creator><pubDate>Mon, 01 Apr 2019 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/how-to-use-static-analysis-to-enforce-sei-cert-coding-standards-for-iot-applications/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Security-Related Requirements</category><category>Secure Coding</category><category>Cyber Risk and Resilience Management</category><category>Static Analysis</category><category>Cybersecurity</category><category>Secure Development</category><category>Cyber Missions</category><category>Best Practices in Network Security</category></item><item><title>A Fighting Chance: Arming the Analyst in the Age of Big Data</title><link>https://www.sei.cmu.edu/blog/a-fighting-chance-arming-the-analyst-in-the-age-of-big-data/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>The 2017 SEI Year in Review highlights the work of the institute undertaken from October 1, 2016, to September 30, 2017. This blog post, which was published in the 2017 Year in Review, highlights the work of three SEI researchers....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Douglas Schmidt</dc:creator><pubDate>Mon, 26 Mar 2018 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/a-fighting-chance-arming-the-analyst-in-the-age-of-big-data/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Big Data</category><category>Data Modeling and Analytics</category><category>Static Analysis</category></item><item><title>Verifying Evolving Software</title><link>https://www.sei.cmu.edu/blog/verifying-evolving-software/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This SEI Blog post explores the challenges of verifying evolving software and presents research efforts aimed at improving verification techniques and tools.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Arie Gurfinkel</dc:creator><pubDate>Mon, 20 Oct 2014 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/verifying-evolving-software/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Model Checking</category><category>Static Analysis</category><category>Verification</category></item><item><title>Regression Verification for Real-time Embedded Software Systems</title><link>https://www.sei.cmu.edu/blog/regression-verification-for-real-time-embedded-software-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>The DoD relies heavily on mission- and safety-critical real-time embedded software systems (RTESs), which play a crucial role in controlling systems ranging from airplanes and cars to infusion pumps and microwaves.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Arie Gurfinkel</dc:creator><pubDate>Mon, 05 Dec 2011 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/regression-verification-for-real-time-embedded-software-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Model Checking</category><category>Static Analysis</category></item></channel></rss>