News on Monday
more>>
SharePoint Tech Report
more>>


   

 
 
Download Current Issue
ISSUE 2/1/2010 PDF

Need Back Issues?
DOWNLOAD HERE

Receive the print Edition?


 
blogs tab
Visual Studio 2010 Release Candidate Available Today
A Visual Studio 2010 release candidate is available on MSDN.
02/09/2010 09:45 AM EST

Is Microsoft eyeing Office subscription pricing?
Microsoft may be preparing to offer a new Office pricing option called "union," which charges the same for cloud as on-premises.
02/01/2010 09:38 AM EST

Facebook rewrites PHP runtime
Facebook is about to open source its own PHP runtime, written from scratch for speed.
01/30/2010 08:53 PM EST

 

Events calendar tab
2/9/2010 to 2/13/2010
San Francisco
IDG World Expo

2/10/2010 to 2/12/2010
San Francisco
BZ Media

2/17/2010 to 2/25/2010
Atlanta
Python Software Foundation

2/19/2010 to 2/20/2010
Los Angeles
SCALE

2/21/2010 to 2/24/2010
Las Vegas
IBM


 
Most Read Latest News Blog Resources

LDRA adds CERT C standard to test tools suite




October 27, 2008 — 
Test tool provider LDRA is now offering its TBrun unit test tool as a standalone product in an attempt to get more developers writing safety-critical applications for unit testing earlier in the development process.

The company also announced that its entire suite of test tools now supports the security-based CERT C Secure Coding Standard. The announcements were made today at the Embedded Systems Conference in Boston.

The company cited research that it said shows unit testing not being done early or often enough, preventing developers from catching errors and fixing them at a time when the cost is relatively low.

TBrun can do both unit and regression testing, and with a plug-in called TBeXtreme, can enable the creation of test cases and automate test process integration. TBrun can run on Linux, Unix and Windows, and it sells for US$10,000 per seat. The plug-in costs $2,000.

CERT C is a standard for secure coding created by the Carnegie Mellon Software Engineering Institute (CMSEI); version 1.0 was unveiled today at the SD Best Practices conference, also in Boston.

The CERT C standard, according to CMSEI, provides rules and recommendations for secure coding in the C programming language, and is designed to be operating system and platform neutral.

LDRA's TBsecure programming checker plugs in to TBvision, a tool that shows developers how software is performing against known security vulnerabilities, enabling development managers to see how the code measures up against established security metrics. Among the things it addresses are dynamic memory allocation, which can lead to vulnerabilities such as buffer overflows, and other coding practices such as out-of-range array indices and null pointer dereferencing. TBsecure costs $2,000.

LDRA positions its test suite as unique, as it has the ability to send the results of tests back to a requirements tool, so not only are code defects being identified earlier, but deviations from the requirements can also be spotted earlier in the development process, according to John Greenland, vice president of business development for LDRA.

"We see a focus on unit tests, or systems tests, or static analysis—compliance and runtime analysis. No one is tying it back to requirements," Greenland said. "With runtime defect analysis, they're trying to prove a program is error-free, not that it does what it was spec'd out to do. We're trying to prove the program is doing what it's expected to do."


Related Search Term(s): CERT CsecuritytestingCMSEILDRA


Share this link: http://www.sdtimes.com/link/33007
 

Add comment


Name*
Email*  
Country     


  • Comment
  • Preview
Loading