Automated Code Inspection Defect Classification Schema
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current automated code inspection tools lack a comprehensive defect analysis schema to accurately measure the value of their investment in reducing defects in late phase testing and production, making it difficult for organizations to assess the impact of automated code inspections on critical exposure areas and plan effectively for late phase testing and production support.
Innovation Solution
A method and system that classify automated code inspection services' defect output using defect classification field rules and mapping profiles, enabling the interpretation of defects from various code inspection tools like WebKing, CAST, Purify Plus, and AppScan, to generate defect analysis metrics and reports that help in planning and optimizing testing and production processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple automated code inspection tools are purchased to cover all exposures, then the coverage of defect detection is improved, but the cost increases significantly
Solution Approach 1:
The patent combines multiple code inspection tools into a unified platform that integrates various defect detection capabilities. Instead of purchasing separate licenses for each tool, the system merges their functions into a single solution that provides comprehensive coverage across functional, security, memory, and accessibility areas while reducing overall cost.
Solution Approach 2:
The unified code inspection platform performs multiple functions simultaneously - it detects functional defects, security vulnerabilities, memory issues, and accessibility problems all in one system. This multi-functional approach replaces the need for multiple specialized tools, providing broad exposure coverage without proportionally increasing cost.
2Measurement precision
If code inspection services are used without a comprehensive defect analysis schema, then the analysis of defect impact is incomplete, but implementing such a schema increases system complexity
Solution Approach 1:
The patent introduces a classification schema as an intermediary layer between the code inspection tools and the defect analysis process. This schema acts as a mediator that structures defect data into standardized categories (functional, security, memory, accessibility), enabling precise impact assessment without requiring complex custom analysis logic in the inspection tools themselves.
Solution Approach 2:
The system changes the parameters of defect analysis by implementing a standardized classification framework with specific categories and metrics. This transforms unstructured defect data into classified information that can be systematically analyzed for impact, converting a complex analytical problem into a structured parameter-based assessment.
3Loss of time
If defects are fixed late in the development cycle, then the time to market is reduced, but the cost of fixing defects increases significantly
Solution Approach 1:
The patent performs preliminary defect detection and classification during early development phases using automated code inspection tools. By identifying and addressing defects early in the development cycle rather than waiting for late-stage testing, the system prevents defects from propagating to later phases where they would be more expensive and time-consuming to fix.
Solution Approach 2:
The system implements continuous feedback loops where defect detection results are immediately classified and fed back to developers for correction. This real-time feedback mechanism enables rapid defect resolution during development, preventing defects from reaching late testing phases and thereby reducing both the cost and time impact of defect fixing.
Data Source
AI summary
A method is implemented in a computer infrastructure having computer executable code tangibly embodied on a computer readable storage medium having programming instructions. The programming instructions are operable to receive a tool error output determined by a code inspection tool and select at least one defect classification mapping profile based on the code inspection tool. Additionally, the programming instructions are operable to map the tool error output to one or more output classifications using the selected at least one defect classification mapping profile and generate at least one report based on the one or more output classifications.


