The University of Queensland Homepage
School of ITEE ITEE Main Website

  Evaluating and Categorizing Coverity Fault Warnings

Evaluating and Categorizing Coverity Fault Warnings

Speaker: Suzanna Schmeelk, Yahoo!/The College of William and Mary/Rutgers

When: 10:00, Thursday 6th November 2008

Venue: 78-421

In this talk, I discuss how we improved classification and prioriti! zation of by Coverity. We present our findings from analyzing three code bases totaling approximately 3.6M lines of code (LOC). Coverity found 1.2K potential fault warnings as follows: 52.29% correct and 47.71% false/noise. The 52.29% correctly reported faults were further prioritized based on severity. Finally, we connected Coverity's classification to a standard software weakness schema, Common Weakness Enumeration (CWE) to standardized discourse.

Bio: Suzanna Schmeelk is a PhD Candidate at The College of William and Mary as well as an EdD Candidate at Rutgers-The State University of New Jersey. Her research spans networking, compilers, security and education. She has spent the last two summers as a member of the security team at Yahoo! in Sunnyvale, California. She is a member of the ACM, the TRUST and the IEEE Computer Society. On the side, she is an extensive traveler having visited over 35 countries.

 

Hospitality: Cristina Cifuentes

Contact: Robert Colvin (SSE seminar co-ordinator) (robert@itee.uq.edu.au)

SSE seminar web page: http://www.itee.uq.edu.au/~sse/Seminars.html