LDRA adds CERT C standard to test tools suite



Email    print   
October 27, 2008 —  Test tool provider LDRA is now offering its TBrun unit test tool as a standalone product in an attempt to get more developers writing safety-critical applications for unit testing earlier in the development process.

The company also announced that its entire suite of test tools now supports the security-based CERT C Secure Coding Standard. The announcements were made today at the Embedded Systems Conference in Boston.

The company cited research that it said shows unit testing not being done early or often enough, preventing developers from catching errors and fixing them at a time when the cost is relatively low.

TBrun can do both unit and regression testing, and with a plug-in called TBeXtreme, can enable the creation of test cases and automate test process integration. TBrun can run on Linux, Unix and Windows, and it sells for US$10,000 per seat. The plug-in costs $2,000.

CERT C is a standard for secure coding created by the Carnegie Mellon Software Engineering Institute (CMSEI); version 1.0 was unveiled today at the SD Best Practices conference, also in Boston.

The CERT C standard, according to CMSEI, provides rules and recommendations for secure coding in the C programming language, and is designed to be operating system and platform neutral.

LDRA's TBsecure programming checker plugs in to TBvision, a tool that shows developers how software is performing against known security vulnerabilities, enabling development managers to see how the code measures up against established security metrics. Among the things it addresses are dynamic memory allocation, which can lead to vulnerabilities such as buffer overflows, and other coding practices such as out-of-range array indices and null pointer dereferencing. TBsecure costs $2,000.

LDRA positions its test suite as unique, as it has the ability to send the results of tests back to a requirements tool, so not only are code defects being identified earlier, but deviations from the requirements can also be spotted earlier in the development process, according to John Greenland, vice president of business development for LDRA.

"We see a focus on unit tests, or systems tests, or static analysis—compliance and runtime analysis. No one is tying it back to requirements," Greenland said. "With runtime defect analysis, they're trying to prove a program is error-free, not that it does what it was spec'd out to do. We're trying to prove the program is doing what it's expected to do."




Related Search Term(s): CERT C, security, testing, CMSEI, LDRA


Share this link: http://sdt.bz/33007
 
Most Read Latest News Blog Resources

Add comment


Name*
Email*  
Country     


  • Comment
Loading




close
NEXT ARTICLE
LDRA improves testing suite
Updates to LDRA 7.7 include enhancements to the TBreq and TBvision tools. Editor configuration has also been improved, with the ability for the user to select a default source code editor added Read More...
 
 
 
 
News on Monday
more>>
SharePoint Tech Report
more>>


   

 
 

Download Current Issue
FEBRUARY 2012 PDF ISSUE

Need Back Issues?
DOWNLOAD HERE

Want to subscribe?


 
blogs tab
Are you at risk for burnout?
Burnout is a severe problem and it can strike at any time. Here's how to tell if you are nearing the edge.
02/09/2012 02:16 PM EST

Agility, mom, and apple pie
If we're to evaluate the state-of-the-art in software development, we should start with the values espoused in the Agile Manifesto.
02/07/2012 11:57 AM EST

RIM woos developers with free tablet
How do you get more apps ported to the BlackBerry PlayBook? By giving every developer a free tablet, of course!
02/04/2012 01:57 PM EST

GitHire: Use Headhunters to Find Your Perfect Programmer
Are you a hiring manager tired of scouring the job boards? Check out this new service that will find 5 people interested in your jobs.
02/03/2012 12:17 PM EST

Facebook claims hacker cred
Facebook's SEC S-1 filing form includes a short essay on the Hacker Way by Mark Zuckerberg himself.
02/02/2012 08:26 AM EST

Ryan Dahl steps down
Ryan Dahl, creator of Node.js, steps back from his position as gatekeeper for the project.
02/01/2012 04:58 PM EST

 
Events calendar tab
2/13/2012 to 2/16/2012
Santa Clara
TechWeb

2/26/2012 to 2/29/2012
San Francisco
BZ Media

2/27/2012 to 3/2/2012
San Francisco
RSA

3/4/2012 to 3/7/2012
Las Vegas
IBM Tivoli

3/5/2012 to 3/9/2012
San Francisco
TechWeb