System and method to classify automated code inspection services defect output for defect analysis
Claim Score by NHIP
Abstract
A method is implemented in a computer infrastructure having computer executable code tangibly embodied on a computer readable storage medium having programming instructions. The programming instructions are operable to receive a tool error output determined by a code inspection tool and select at least one defect classification mapping profile based on the code inspection tool. Additionally, the programming instructions are operable to map the tool error output to one or more output classifications using the selected at least one defect classification mapping profile and generate at least one report based on the one or more output classifications.

Term
Projected expiry 16 May 2032.
- Priority and filed
- Published
- Today
- Projected expiry
25 claims: 4 independent, 21 dependent
- 1A method implemented in a computer infrastructure having computer executable code tangibly embodied on a computer readable storage medium having programming instructions operable to:receive a tool error output determined by a code inspection tool;select at least one defect classification mapping profile based on the code inspection tool;map the tool error output to one or more output classifications using the selected at least one defect classification mapping profile;and generate at least one report based on the one or more output classifications.
- 16Broadest claimClaim Score 66, broad(NHIP)A system, comprising:an error output receiving tool operable to receive a tool error output determined by a code inspection tool;a selection tool operable to select at least one defect classification mapping profile based on the code inspection tool;a defect classification mapping tool operable to map the tool error output to one or more output classifications using the selected at least one defect classification mapping profile;and a report generation tool operable to generate at least one report based on the one or more output classifications.
- 24A computer program product comprising a computer usable storage medium having readable program code embodied in the storage medium, the computer program product includes at least one component operable to:receive a tool error output determined by a code inspection tool;select at least one defect classification mapping profile based on the code inspection tool;map the tool error output to one or more output classifications using the selected at least one defect classification mapping profile;and generate at least one defect analysis metric based on the one or more output classifications.
- 25A computer system for classifying automated code inspection services defect output for defect analysis, the system comprising:a CPU, a computer readable memory and a computer readable storage media;first program instructions to receive a tool error output determined by a code inspection tool;second program instructions to select at least one defect classification mapping profile based on the code inspection tool;third program instructions to map the tool error output to one or more output classifications using the selected at least one defect classification mapping profile;and fourth program instructions to generate at least one defect analysis metric based on the one or more output classifications, wherein the first, second, third and fourth program instructions are stored on the computer readable storage media for execution by the CPU via the computer readable memory.
Independent claims4
111 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
0001The present invention generally relates to defect analysis, and more particularly, to a method and system to classify automated code inspection services defect output for defect analysis.
BACKGROUND
0002While software systems continue to grow in size and complexity, business demands continue to require shorter development cycles. This has led software developers to compromise on functionality, time to market, and quality of software products. Furthermore, the increased schedule pressures and limited availability of resources and skilled labor can lead to problems such as incomplete design of software products, inefficient testing, poor quality, high development and maintenance costs, and the like. This may lead to poor customer satisfaction and a loss of market share for companies developing software.
0003To improve product quality, many organizations devote an increasing share of their resources to testing and identifying problem areas related to software and the process of software development. Accordingly, it is not unusual to include a quality assurance team in software development projects to identify defects in the software product during and after development of a software product. By identifying and resolving defects before marketing the product to customers, software developers can assure customers of the reliability of their products, and reduce the occurrence of post-sale software fixes such as patches and upgrades which may frustrate their customers.
0004Software testing may involve verifying the correctness, completeness, security, quality, etc. of a product. During testing, a technical investigation may be performed by, for example, executing a program or application with the intent to find errors. If errors are found, one or more areas in the software code may be identified based on the errors. Therefore, developers may alter the code in the identified regions to obviate the error.
0005After a defect has been fixed, data regarding the defect, and the resolution of the defect, may be stored in a database. The defects may be classified and analyzed as a whole using, for example, Orthogonal Defect Classification (ODC) and/or a defect analysis starter/defect reduction method (DAS/DRM), which is described in U.S. Patent Application Publication No. 2006/0265188, U.S. Patent Application Publication No. 2006/0251073, and U.S. Patent Application Publication No. 2007/0174023, the contents of each of which are hereby incorporated by reference herein in their entirety. ODC is a commonly used complex quality assessment schema for understanding code related defects uncovered during testing.
0006It is widely accepted in the testing industry that the least expensive defects to fix are those found earliest in the life cycle. However, a problem in complex system integration testing is that there may be very few comprehensive opportunities for projects to remove defects cost effectively prior to late phase testing, and by that point in the life cycle (i.e., late phase testing) defects are relatively expensive to fix. Furthermore, for many projects there are particular kinds of high impact exposures, e.g., defects in the area of security, that are critical to find and fix, but are also difficult to test.
0007There are numerous automated code inspection tools available on the market today designed to address this problem; however, for many projects, it is not cost effective for an organization to purchase licenses for all of the tools needed to cover all of the exposures of interest to them. Moreover, even if it was cost effective for an organization to purchase licenses for all of the tools needed to cover all of the exposures, there is no way to understand the return on this investment in terms of the impact on reducing the numbers of defects found in late phase testing and in production.
0008As a result of these impracticalities, few complex system integration projects avail themselves of automated code inspection defect removal strategies, even though applying them to unit tested code prior to beginning system testing is one of the most cost effective options available. This problem has been addressed in part by, e.g., a service provider assembling a set of code inspection tools designed to address four areas, as shown in TABLE 1 below.
0000<tables id="TABLE-US-00001" num="00001"><table frame="none" colsep="0" rowsep="0" pgwide="1"><tgroup align="left" colsep="0" rowsep="0" cols="5"><colspec colname="1" colwidth="56pt" align="center" /><colspec colname="2" colwidth="63pt" align="left" /><colspec colname="3" colwidth="56pt" align="left" /><colspec colname="4" colwidth="49pt" align="left" /><colspec colname="5" colwidth="35pt" align="center" /><thead><row><entry namest="1" nameend="5" rowsep="1">TABLE 1</entry></row><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row><row><entry /><entry /><entry /><entry /><entry>Dynamic</entry></row><row><entry /><entry /><entry>Technologies</entry><entry>Static Code</entry><entry>Code</entry></row><row><entry>Types of analysis:</entry><entry>Functional Outputs</entry><entry>supported</entry><entry>analysis</entry><entry>analysis</entry></row><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry>1</entry><entry>Industry and Best</entry><entry>Maintainability,</entry><entry>COBOL, C++,</entry><entry>X</entry></row><row><entry /><entry>Practice Standards</entry><entry>Robustness,</entry><entry>J2EE/Java,</entry></row><row><entry /><entry>Compliance</entry><entry>Quality,</entry><entry>ABAP,</entry></row><row><entry /><entry /><entry>Changeability,</entry><entry>Microsoft.NET</entry></row><row><entry /><entry /><entry>Performance,</entry></row><row><entry /><entry /><entry>Programming</entry></row><row><entry /><entry /><entry>Practices,</entry></row><row><entry /><entry /><entry>Architectural</entry></row><row><entry /><entry /><entry>Design,</entry></row><row><entry /><entry /><entry>Documentation</entry></row><row><entry>2</entry><entry>Security</entry><entry>Application</entry><entry>Web</entry><entry>X</entry></row><row><entry /><entry /><entry>Privacy,</entry><entry>Applications</entry></row><row><entry /><entry /><entry>Authentication,</entry></row><row><entry /><entry /><entry>Authorization,</entry></row><row><entry /><entry /><entry>Client-side</entry></row><row><entry /><entry /><entry>Attacks,</entry></row><row><entry /><entry /><entry>Command</entry></row><row><entry /><entry /><entry>Execution,</entry></row><row><entry /><entry /><entry>Information</entry></row><row><entry /><entry /><entry>Disclosure,</entry></row><row><entry /><entry /><entry>Location, Logical</entry></row><row><entry /><entry /><entry>Attacks</entry></row><row><entry>3</entry><entry>Memory</entry><entry>Memory leaks,</entry><entry>Web</entry><entry>X</entry></row><row><entry /><entry>Management</entry><entry>Memory access</entry><entry>Applications</entry></row><row><entry /><entry /><entry>errors, Memory</entry></row><row><entry /><entry /><entry>state tracking,</entry></row><row><entry /><entry /><entry>Quantify for</entry></row><row><entry /><entry /><entry>application</entry></row><row><entry /><entry /><entry>performance</entry></row><row><entry /><entry /><entry>profiling,</entry></row><row><entry /><entry /><entry>Coverage</entry></row><row><entry>4</entry><entry>Usability and</entry><entry>Accessibility</entry><entry>Web</entry><entry>X</entry></row><row><entry /><entry>Accessibility</entry><entry /><entry>Applications</entry></row><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0009With this approach, for example, a project (e.g., a software project of an organization) can purchase code inspection services from the service provider on an as-needed basis without requiring any tool purchase or licensing costs for tools they may only need to leverage on a limited basis. Thus, a project may, for example, utilize a plurality of code inspection services (e.g., specifically tailored for their project) and receive code inspection services reports from the service provider. By assembling a set of code inspection tools and providing for purchase of code inspection services on an as-needed basis, utilization of these code inspection services is rendered more cost effective.
0010However, no defect analysis schema capable of accurately measuring value received from performing specific automated code inspection activities is known to exist. Thus, there is no way to understand the return on this investment (e.g., the purchase of code inspection services) in terms of the impact on reducing the numbers of defects found in late phase testing and in production. That is, the code inspection services reports (for example, from the plurality of code inspection services, e.g., specifically tailored for their project) do not interpret defects uncovered via the automated code inspection subscription service. Rather, such code inspection service reports, for example, only identify defects uncovered via the automated code inspection subscription service. Thus, this automated code inspection subscription service does not allow projects to accurately assess the impact of automated code inspections on, for example, critical exposure areas and does not allow for effective planning of, for example, late phase testing and production support needs.
0011Accordingly, there exists a need in the art to overcome the deficiencies and limitations described hereinabove.
SUMMARY
0012In a first aspect of the invention, a method is implemented in a computer infrastructure having computer executable code tangibly embodied on a computer readable storage medium having programming instructions. The programming instructions are operable to receive a tool error output determined by a code inspection tool and select at least one defect classification mapping profile based on the code inspection tool. Additionally, the programming instructions are operable to map the tool error output to one or more output classifications using the selected at least one defect classification mapping profile and generate at least one report based on the one or more output classifications.
0013In another aspect of the invention, a system comprises an error output receiving tool operable to receive a tool error output determined by a code inspection tool and a selection tool operable to select at least one defect classification mapping profile based on the code inspection tool. Additionally, the system comprises a defect classification mapping tool operable to map the tool error output to one or more output classifications using the selected at least one defect classification mapping profile and a report generation tool operable to generate at least one report based on the one or more output classifications.
0014In an additional aspect of the invention, a computer program product comprising a computer usable storage medium having readable program code embodied in the medium is provided. The computer program product includes at least one component operable to receive a tool error output determined by a code inspection tool and select at least one defect classification mapping profile based on the code inspection tool. Additionally, the at least one component is operable to map the tool error output to one or more output classifications using the selected at least one defect classification mapping profile and generate at least one defect analysis metric based on the one or more output classifications.
0015In a further aspect of the invention, a computer system for classifying automated code inspection services defect output for defect analysis, the system comprises a CPU, a computer readable memory and a computer readable storage media. Additionally, the system comprises first program instructions to receive a tool error output determined by a code inspection tool and second program instructions to select at least one defect classification mapping profile based on the code inspection tool. Furthermore, the system comprises third program instructions to map the tool error output to one or more output classifications using the selected at least one defect classification mapping profile and fourth program instructions to generate at least one defect analysis metric based on the one or more output classifications. The first, second, third and fourth program instructions are stored on the computer readable storage media for execution by the CPU via the computer readable memory
BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS
0016The present invention is described in the detailed description which follows, in reference to the noted plurality of drawings by way of non-limiting examples of exemplary embodiments of the present invention.
0017<figref idref="DRAWINGS">FIG. 1</figref> shows an illustrative environment for implementing the steps in accordance with aspects of the invention;
0018<figref idref="DRAWINGS">FIG. 2</figref> shows an exemplary depiction of a high level flow in accordance with aspects of the invention;
0019<figref idref="DRAWINGS">FIGS. 3-18</figref> illustrate exemplary defect classification mapping profiles for different functional areas of code for a first code inspection service in accordance with aspects of the invention;
0020<figref idref="DRAWINGS">FIG. 19</figref> illustrates an exemplary defect classification mapping profile for a second code inspection service in accordance with aspects of the invention;
0021<figref idref="DRAWINGS">FIG. 20</figref> illustrates an exemplary defect classification mapping profile for a third code inspection service in accordance with aspects of the present invention;
0022<figref idref="DRAWINGS">FIG. 21</figref> illustrates an additional exemplary defect classification mapping profile for a fourth code inspection service in accordance with aspects of the invention;
0023<figref idref="DRAWINGS">FIGS. 22-41</figref> illustrate exemplary defect classification mapping profiles which list possible tool error outputs for a fifth code inspection service in accordance with aspects of the invention;
0024<figref idref="DRAWINGS">FIG. 42</figref> illustrates an exemplary assessment including a rating of results against expectation for each of technical quality, security, memory and accessibility in accordance with aspects of the present invention;
0025<figref idref="DRAWINGS">FIG. 43</figref> illustrates an exemplary quantification of error types in accordance with aspects of the present invention;
0026<figref idref="DRAWINGS">FIGS. 44-46</figref> illustrate exemplary histograms in accordance with aspects of the present invention;
0027<figref idref="DRAWINGS">FIG. 47</figref> illustrates an exemplary illustration of defect artifact types mapped to a process point when those defects are injected in accordance with aspects of the present invention;
0028<figref idref="DRAWINGS">FIGS. 48-58</figref> illustrate additional exemplary histograms in accordance with aspects of the present invention;
0029<figref idref="DRAWINGS">FIG. 59</figref> illustrates a trigger summary in accordance with aspects of the invention; and
0030<figref idref="DRAWINGS">FIG. 60</figref> shows an exemplary flow for performing aspects of the present invention.
DETAILED DESCRIPTION
0031The present invention generally relates to defect analysis, and more particularly, to system and method to classify automated code inspection services defect output for defect analysis. The present invention utilizes defect classification field rules (e.g., in accordance with a common schema) for classifying and interpreting defects uncovered via automated code inspection subscription service. More specifically, the present invention establishes automated classification rules to interpret the defects uncovered via various automated code inspection tools (e.g., WebKing®, CAST, Purify Plus™, AppScan®, and ABAP Code Optimizer, amongst other code inspection tools) so that projects can more effectively plan late phase testing needs and reduce high risk or impact defects that would likely otherwise have escaped into production. (Purify Plus and AppScan are trademarks of International Business Machines Corporation in the United States, other countries, or both. WebKing is a trademark of Parasoft Corporation in the United States, other countries, or both.)
0032Implementing the present invention, leveraging multiple code inspection tools in a defect removal/analysis test service at the unit test phase of the life cycle, enables projects to realize significant cost savings because, for example, finding and fixing high value defects at this relatively early phase (i.e., unit test) is far less expensive than attempting to find and fix defects in any of the late phase tests (e.g., after unit test), or especially in production. The present invention also enables projects to measure the impact of finding and/or fixing these defects on later test phases. For example, if the project has already adequately addressed security concerns in the automated code inspection, the organization can reduce or eliminate test cases from the execution plan and move to production earlier without sacrificing quality or increasing risk.
0033In embodiments, projects can select any combination of tools to be applied to their code (e.g., WebKing, CAST, Purify Plus, AppScan, and ABAP Code Optimizer). Once the selected tools have been applied to the code under test, the output from the inspection (i.e., from the selected tools) is received by a report generation system including a defect classification mapping tool in accordance with the present invention. As discussed further below, the defect classification mapping tool applies a set of defect classification rules and, in embodiments, a report generation tool produces, for example, an overall defect analysis report based on the output of the defect classification mapping tool.
0034By implementing the present invention, an organization may allow projects to accurately assess the impact of automated code inspections on critical exposure areas, which can in turn be used to more effectively plan late phase testing and production support needs. For example, the defect analysis report will provide insights that will enable projects to optimize, for example, their go-forward test planning.
System Environment
0035As will be appreciated by one skilled in the art, the present invention may be embodied as a system, method or computer program product. Accordingly, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a “circuit,” “module” or “system.” Furthermore, the present invention may take the form of a computer program product embodied in any tangible medium of expression having computer-usable program code embodied in the medium.
0036Any combination of one or more computer usable or computer readable medium(s) may be utilized. The computer-usable or computer-readable medium may be, for example but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, device, or propagation medium. More specific examples (a non-exhaustive list) of the computer-readable medium would include the following: <ul id="ul0001" list-style="none"><li id="ul0001-0001" num="0000"><ul id="ul0002" list-style="none"><li id="ul0002-0001" num="0037">an electrical connection having one or more wires,</li><li id="ul0002-0002" num="0038">a portable computer diskette,</li><li id="ul0002-0003" num="0039">a hard disk,</li><li id="ul0002-0004" num="0040">a random access memory (RAM),</li><li id="ul0002-0005" num="0041">a read-only memory (ROM),</li><li id="ul0002-0006" num="0042">an erasable programmable read-only memory (EPROM or Flash memory),</li><li id="ul0002-0007" num="0043">an optical fiber,</li><li id="ul0002-0008" num="0044">a portable compact disc read-only memory (CDROM),</li><li id="ul0002-0009" num="0045">an optical storage device,</li><li id="ul0002-0010" num="0046">a transmission media such as those supporting the Internet or an intranet, or</li><li id="ul0002-0011" num="0047">a magnetic storage device.</li></ul></li></ul>
0048The computer-usable or computer-readable medium could even be paper or another suitable medium upon which the program is printed, as the program can be electronically captured, via, for instance, optical scanning of the paper or other medium, then compiled, interpreted, or otherwise processed in a suitable manner, if necessary, and then stored in a computer memory.
0049In the context of this document, a computer-usable or computer-readable medium may be any medium that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. The computer-usable medium may include a propagated data signal with the computer-usable program code embodied therewith, either in baseband or as part of a carrier wave. The computer usable program code may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc.
0050Computer program code for carrying out operations of the present invention may be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the “C” programming language or similar programming languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network. This may include, for example, a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider).
0051<figref idref="DRAWINGS">FIG. 1</figref> shows an illustrative environment <b>10</b> for managing the processes in accordance with the invention. To this extent, the environment <b>10</b> includes a server or other computing system <b>12</b> that can perform the processes described herein. In particular, the server <b>12</b> includes a computing device <b>14</b>. The computing device <b>14</b> can be resident on a network infrastructure or computing device of a third party service provider (any of which is generally represented in <figref idref="DRAWINGS">FIG. 1</figref>). In embodiments, the environment <b>10</b> may be designated as a report generation system <b>210</b>.
0052The computing device <b>14</b> also includes a processor <b>20</b>, memory <b>22</b>A, an I/O interface <b>24</b>, and a bus <b>26</b>. The memory <b>22</b>A can include local memory employed during actual execution of program code, bulk storage, and cache memories which provide temporary storage of at least some program code in order to reduce the number of times code must be retrieved from bulk storage during execution. In addition, the computing device includes random access memory (RAM), a read-only memory (ROM), and an operating system (O/S).
0053The computing device <b>14</b> is in communication with the external I/O device/resource <b>28</b> and the storage system <b>22</b>B. For example, the I/O device <b>28</b> can comprise any device that enables an individual to interact with the computing device <b>14</b> or any device that enables the computing device <b>14</b> to communicate with one or more other computing devices using any type of communications link. The external I/O device/resource <b>28</b> may be for example, a handheld device, PDA, handset, keyboard etc. In embodiments, the defect classification mapping profiles may be stored in storage system <b>22</b>B or another storage system, which may be, for example, a database.
0054In general, the processor <b>20</b> executes computer program code (e.g., program control <b>44</b>), which can be stored in the memory <b>22</b>A and/or storage system <b>22</b>B. Moreover, in accordance with aspects of the invention, the program control <b>44</b> controls the error output receiving tool <b>25</b>, the selection tool <b>30</b>, the defect classification mapping tool <b>35</b> and the report generation tool <b>40</b>. While executing the computer program code, the processor <b>20</b> can read and/or write data to/from memory <b>22</b>A, storage system <b>22</b>B, and/or I/O interface <b>24</b>. The program code executes the processes of the invention such as, for example, the processes of the output receiving tool <b>25</b>, the selection tool <b>30</b>, the defect classification mapping tool <b>35</b> and the report generation tool <b>40</b>. The bus <b>26</b> provides a communications link between each of the components in the computing device <b>14</b>.
0055The computing device <b>14</b> can comprise any general purpose computing article of manufacture capable of executing computer program code installed thereon (e.g., a personal computer, server, etc.). However, it is understood that the computing device <b>14</b> is only representative, of various possible equivalent-computing devices that may perform the processes described herein. To this extent, in embodiments, the functionality provided by the computing device <b>14</b> can be implemented by a computing article of manufacture that includes any combination of general and/or specific purpose hardware and/or computer program code. In each embodiment, the program code and hardware can be created using standard programming and engineering techniques, respectively.
0056Similarly, the computing infrastructure <b>12</b> is only illustrative of various types of computer infrastructures for implementing the invention. For example, in embodiments, the server <b>12</b> comprises two or more computing devices (e.g., a server cluster) that communicate over any type of communications link, such as a network, a shared memory, or the like, to perform the process described herein. Further, while performing the processes described herein, one or more computing devices on the server <b>12</b> can communicate with one or more other computing devices external to the server <b>12</b> using any type of communications link. The communications link can comprise any combination of wired and/or wireless links; any combination of one or more types of networks (e.g., the Internet, a wide area network, a local area network, a virtual private network, etc.); and/or utilize any combination of transmission techniques and protocols.
0057As illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, the error output receiving tool <b>25</b> is operable to receive the output of selected code inspection services. Additionally, the selection tool <b>30</b> is operable to select an appropriate defect classification mapping profile from a storage system (e.g., storage system <b>22</b>B) containing classification mapping profiles for each of the code inspection services. Furthermore, the defect classification mapping tool <b>35</b> is operable to map the output of the selected code inspection services using the selected defect classification mapping profile(s). The report generation tool <b>40</b> is operable to generate a report that includes defect analysis metrics, e.g., the processes described herein. The error output receiving tool <b>25</b>, the selection tool <b>30</b>, the defect classification mapping tool <b>35</b> and the report generation tool <b>40</b> can be implemented as one or more program code in the program control <b>44</b> stored in memory <b>22</b>A as separate or combined modules.
Error Output Receiving Tool
0058The error output receiving tool <b>25</b> is operable to receive the output of selected code inspection services. More specifically, as discussed further below, in embodiments, the output of selected code inspection services will contain, for example, one or more error texts. Each error text may be specific to a particular type of error detected by a particular code inspection service. The error output receiving tool <b>25</b> is operable to receive one or more error texts from one or more particular code inspection services, as described further below.
0059In embodiments, the error output receiving tool <b>25</b> is operable to receive an indication of which code inspection tools were utilized in the code inspection services based on the received output of selected code inspection services. Additionally, in embodiments, the error output receiving tool <b>25</b> is operable to determine which code inspection tools were utilized in the code inspection services based on the received output of selected code inspection services. For example, in embodiments, the error output receiving tool <b>25</b> may access a listing of the different possible outputs of the code inspection services (e.g., error texts) for the different code inspection services (e.g., WebKing, CAST, Purify Plus, AppScan, and ABAP Code Optimizer). The error output receiving tool <b>25</b> may compare the output received from the selected code inspection services (e.g., the error texts), for example, for a particular organization's code, to the listing of the different possible outputs to determine which code inspection service or services (e.g., WebKing, CAST, Purify Plus, AppScan, and ABAP Code Optimizer) have been used to test the organization's code. As discussed further below, the determination of which code inspection services have been used to test an organization's code is sent to the selection tool <b>30</b> to enable the selection tool <b>30</b> to select appropriate defect classification mapping profiles.
Selection Tool
0060The selection tool <b>30</b> is operable to select an appropriate defect classification mapping profile from a defect analysis starter (DAS)/defect reduction method (DRM) storage system <b>220</b> (which may be stored in storage system <b>22</b>B shown in <figref idref="DRAWINGS">FIG. 1</figref>) containing classification mapping profiles for each of the code inspection services. That is, the output of code inspection services, e.g., error texts, may be specific to particular code inspection services. As such, the selection tool <b>30</b> is operable to select an appropriate defect classification mapping profile, e.g., one or more defect classification mapping profiles that are specific to the one or more code inspection services used to test code. For example, if the WebKing code inspection tool was used to test, e.g., an organization's code (for example as determined by the error output receiving tool <b>25</b>), then the selection tool <b>30</b> is operable to select one or more defect classification mapping profiles specific to the WebKing code inspection tool. The selected one or more defect classification mapping profiles is utilized by the defect classification mapping tool <b>35</b> to enable the defect classification mapping tool <b>35</b> to map the output of the selected code inspection services (e.g., the error texts) using the selected defect classification mapping profile(s), as discussed further below.
Mapping Tool
0061The defect classification mapping tool <b>35</b> is operable to map the output of the selected code inspection services using the selected defect classification mapping profile(s), e.g., selected by the selection tool <b>30</b>. For example, as discussed further below, the defect classification mapping tool <b>35</b> may receive the output of selected code inspection services (e.g., from the error output receiving tool <b>25</b>) and quantify the occurrences of each possible tool error outputs for each of the selected code inspection services.
0062Additionally, the defect classification mapping tool <b>35</b> is operable to map each of the error outputs to its respective classifications (e.g., target, trigger, impact, type, qualifier and severity level, amongst other classifications) using the appropriate defect classification mapping profile defect. Furthermore, the defect classification mapping tool <b>35</b> is operable to quantify the defects by one or more of the classifications (e.g., target, trigger, impact, type, qualifier and severity level, amongst other classifications).
Report Generation Tool
0063In accordance with further aspects of the invention, the report generation tool <b>40</b> is operable to generate a report containing, e.g., defect analysis metrics, using the classified tool output information, e.g., received from the defect classification mapping tool <b>35</b>. In embodiments, the report generation tool <b>40</b> may report defect discoveries and provide detailed reports of findings, including mitigated risk. Additionally, the generated reports may be used to analyze and/or measure the results, and highlight error prone areas. Furthermore, the present invention may be used to quantify the extent to which specific defect categories were shifted earlier in the software life cycle (e.g., when defects may be less expensive to remedy), and to identify opportunities to prevent the injection of the high priority defects. A report may include a Rough Order of Magnitude business case reflecting cost reduction opportunity (for example, earlier defect removal, cycle time reduction, and prevention of defect injection).
0064In embodiments, for example, the report generation tool <b>40</b> may provide a report containing an analysis or assessment. The assessment may include for each of technical quality, security, memory and accessibility, a rating of results against expectation and error prone area identification with implications.
0065Additionally, the report may include an indication of opportunities for improvement. In embodiments, the indication of opportunities for improvement may include trends, implications, opportunities and/or recommendations. Furthermore, the report may include a high level business case including high level cost of initiatives, e.g., reflecting cost reduction opportunity and rough order of magnitude/benefits. Additionally, the report may describe significant and/or critical analysis results, which, for example, may be the metric results rated as the most significant results associated with defect removal (e.g., of the selected one or more code inspection services) and/or in terms of the greatest opportunity to prevent defect injection. The report may also include a histogram of defects found, for example, by tool error category and implications. Exemplary reports in accordance with aspects of the present invention are discussed further below.
Exemplary High Level Flow
0066<figref idref="DRAWINGS">FIG. 2</figref> illustrates a high level flow <b>200</b> in accordance with aspects of the invention. As shown in <figref idref="DRAWINGS">FIG. 2</figref>, a code inspection service <b>205</b> (e.g., an automated code inspection service) is performed on code, e.g., provided by a client, which creates output information (e.g., tool error output <b>215</b>). As described above, in embodiments, a particular client may use a single automated code inspection service or multiple code inspection services. Additionally, a single code inspection service may comprise multiple code inspection tools (e.g., WebKing, CAST, Purify Plus, AppScan, and ABAP Code Optimizer). The tool error output <b>215</b> is received by the report generation system <b>210</b> (also shown in <figref idref="DRAWINGS">FIG. 1</figref>).
0067In embodiments, the report generation system <b>210</b> receives the output <b>215</b> of selected code inspection services, e.g., using the error output receiving tool <b>25</b> (shown in <figref idref="DRAWINGS">FIG. 1</figref>), and accesses one or more appropriate defect classification mapping profiles <b>217</b> from a DAS/DRM storage system <b>220</b>, e.g., using the selection tool <b>30</b> (shown in <figref idref="DRAWINGS">FIG. 1</figref>). Additionally, the report generation system <b>210</b> maps the output of the selected code inspection services using the selected defect classification mapping profile(s) <b>217</b>, e.g., using the defect classification mapping tool <b>35</b>, and generate a report that includes defect analysis metrics, e.g., using the report generation tool <b>40</b> (shown in <figref idref="DRAWINGS">FIG. 1</figref>).
0068For example, as discussed further below, if a WebKing automated code inspection service has been utilized, the report generation system <b>210</b> (e.g., the error output receiving tool <b>25</b>) receives the output <b>215</b> of selected code inspection services. Additionally, the report generation system <b>210</b> accesses the WebKing defect classification mapping profile(s) <b>222</b> from the DAS/DRM storage system <b>220</b> (e.g., using the selection tool <b>30</b>). Utilizing the appropriate defect classification mapping profile(s), the report generation system <b>210</b> (e.g., the defect classification mapping tool <b>35</b>) classifies (or maps) the tool output information (e.g., the tool error output <b>215</b>). The report generation system <b>210</b> (e.g., the report generation tool <b>40</b>) then uses the classified tool output information to generate a report containing, e.g., defect analysis metrics.
Defect Classification Mapping Profiles
0069<figref idref="DRAWINGS">FIGS. 3-41</figref> illustrate exemplary defect classification mapping profiles for five code inspection tools (WebKing, CAST, Purify Plus, AppScan, and ABAP Code Optimizer) in accordance with aspects of the invention. However, these exemplary defect classification mapping profiles should not be considered exhaustive of all defect classification mapping profiles. That is, the invention contemplates that other code inspection tools may be utilized. As such, the invention contemplates that additional defect classification mapping profiles may be tailored to these other code inspection tools. Additionally, while <figref idref="DRAWINGS">FIGS. 3-41</figref> illustrate exemplary defect classification mapping profiles in a tabular format, the invention contemplates other formats for the defect classification mapping profiles. As such, the exemplary defect classification mapping profiles of <figref idref="DRAWINGS">FIGS. 3-41</figref> should not be construed as limiting the present invention.
0070<figref idref="DRAWINGS">FIGS. 3-18</figref> illustrate exemplary defect classification mapping profiles for different functional areas of code for the WebKing code inspection service. More specifically, <figref idref="DRAWINGS">FIGS. 3-18</figref> illustrate exemplary defect classification mapping profiles for a WebKing error output (e.g., one of the tools included in the code inspection service) to five specific Defect Reduction Method (DRM) fields/attributes: trigger, target, impact, type and qualifier, and a severity level.
0071A “trigger” indicates how a defect was discovered (e.g., the circumstances surrounding the defect discovery). A “target” indicates a high level cause of the defect. As with the present invention, the code inspection services identify code defects, for each of the exemplary defect classification mapping profiles, the target should be “requirements/design/code.” An “impact” indicates an impact to a user. For example, “accessibility” indicates whether a handicapped individual can attain access.
0072A “type” (or “artifact type”) indicates what was fixed, specifying, for example, the size and complexity of what was fixed. For example, were just a few lines of code fixed or was a large amount of code fixed. Exemplary types include “assignment,” indicating a simple fix, “checking,” indicating a more complex fix, and “algorithm,” which is more complex than both the assignment and checking types. A “qualifier” indicates whether errors found are related to, e.g., incorrect, extraneous or missing code. In accordance with aspects of the invention, by combining the type and qualifier, the present invention is able to determine where an error was injected into the project. A “severity” indicates a relative severity of the error. In embodiments, depending upon which code inspection services are utilized by a client, the severity may have a value of between 1 (most severe) and 3 (least severe), with other severity levels contemplated by the invention. The severity may provide insight, for example, as to where processes may be weak.
0073<figref idref="DRAWINGS">FIG. 3</figref> shows an exemplary defect classification mapping profile <b>300</b> for “Images and Animations” functional area of a WebKing code inspection service. As shown in <figref idref="DRAWINGS">FIG. 3</figref>, exemplary defect classification mapping profile <b>300</b> includes a tool error output column <b>305</b>, which lists possible tool error outputs <b>310</b> (e.g., error text). As should be understood, the list of possible tool error outputs <b>310</b> is not exhaustive, and the invention contemplates that other possible tool error outputs may also be included in a defect classification mapping profile, in accordance with aspects of the invention. For example, in embodiments, the list of possible tool error outputs <b>310</b> may be dynamic, such that new possible tool error outputs may be added to the tool error output column <b>305</b>.
0074Additionally, the invention contemplates that a particular tool error output for a particular code inspection tool representative of a particular code defect may change. For example, newer versions of a code inspection tool may identify a defect by with a new tool error output (as compared to an older version of the code inspection tool). As such, the list of possible tool error outputs <b>310</b> is not exhaustive, and the invention contemplates that other possible tool error outputs may also be included in a defect classification mapping profile, in accordance with aspects of the invention.
0075As shown in <figref idref="DRAWINGS">FIG. 3</figref>, with defect classification mapping profile <b>300</b> each of the possible tool error outputs <b>310</b> (e.g., error texts) include an acronym <b>315</b>, text <b>320</b> and bracketed information <b>325</b>. The acronym <b>315</b> (e.g., “SV,” “PSV” or “V”) indicates whether the defect is a severe violation, possible severe violation or a violation, respectively. The text <b>320</b> indicates some corrective action and the bracketed information <b>325</b> provides code location information (e.g., pointing a programmer to the appropriate section of code containing the identified error). As those of ordinary skill in the art would readily understand the information contained in the tool error output column <b>305</b>, no further explanation is necessary for an understanding of the present invention.
0076Additionally, <figref idref="DRAWINGS">FIG. 3</figref> includes a tool error output classification <b>330</b> for each of the possible tool error outputs <b>310</b> (e.g., error texts). More specifically, the exemplary defect classification mapping profile <b>300</b> includes a target/trigger/impact column <b>335</b>, which indicates the target, the trigger and the impact for each of the possible tool error outputs <b>310</b>. As shown in <figref idref="DRAWINGS">FIG. 3</figref>, as with the present invention, the code inspection services identify code defects, for each of the exemplary defect classification mapping profiles, the target will be “requirements/design/code.” Moreover, as indicated in <figref idref="DRAWINGS">FIG. 3</figref>, for each of the “Images and Animations” tool error output, the trigger is “variation” and the impact is “accessibility.” As should be understood, while illustrated as a single column, target/trigger/impact column <b>335</b> may be depicted as, e.g., three discrete columns.
0077The exemplary defect classification mapping profile <b>300</b> includes a type column <b>340</b>, which indicates what was fixed, specifying, for example, the size and complexity of what was fixed. As indicated in <figref idref="DRAWINGS">FIG. 3</figref>, types for this exemplary defect classification mapping profile <b>300</b> include “assignment,” and “algorithm.” As discussed above, “assignment,” indicates, for example, a simple fix, whereas “algorithm” indicates, for example, a more complex fix. Additionally, the exemplary defect classification mapping profile <b>300</b> includes a qualifier column <b>345</b>, indicating whether the error found is related to, e.g., incorrect, extraneous or missing code. The exemplary defect classification mapping profile <b>300</b> further includes a severity column <b>350</b>, which indicates a relative severity of the error. In embodiments, depending upon which code inspection services are utilized by a client, the severity may have a value of between 1 (most severe) and 3 (least severe), with other severity values contemplated by the invention.
0078In accordance with aspects of the invention, the values for the tool error output classification <b>330</b> (e.g., the values of columns <b>335</b>, <b>340</b>, <b>345</b> and <b>350</b>) have been determined for each of the possible tool error outputs <b>310</b>. More specifically, values for the tool error output classification <b>330</b> have been determined based on review of historical code defects (e.g., contained in a defect analysis starter/defect reduction method (DAS/DRM) project repository) and, for example, patterns discovered from the historic code defects. That is, as described above, after a defect has been fixed, data regarding the defect (e.g., target, trigger, impact, type and qualifier), and the resolution of the defect, may be stored in a database. For example, the database of past defects (which include, for example, for each defect an indication of the defect's target, trigger, impact, type and qualifier) may be used to determine associations between each possible tool error output <b>310</b> and their respective tool output classifications (e.g., target, trigger, impact, type, qualifier and severity level, amongst other classifications), as exemplified by defect classification mapping profile <b>300</b>.
0079Additionally, in accordance with aspects of the present invention, with exemplary defect classification mapping profile <b>300</b> values for the severity column <b>350</b> may be derived from the acronym <b>315</b> (e.g., “SV,” “PSV” or “V”). For example, a tool error output <b>305</b> indicating a severe violation (SV) is assigned a severity level of “1,” whereas a possible severe violation (PSV) is assigned a severity level of “2,” and a violation (V) is assigned a severity level of “3.”
0080While the exemplary defect classification mapping profile <b>300</b> includes a listing of possible tool error outputs <b>310</b> for each code inspection service, the invention contemplates that additional possible tool error outputs <b>310</b> may arise. For example, a particular code inspection service may designate a new tool error output. As such, the exemplary defect classification mapping profile <b>300</b> (or any other defect classification mapping profile) should not be construed as limiting the present invention.
0081<figref idref="DRAWINGS">FIGS. 4-18</figref> illustrate additional exemplary defect classification mapping profiles <b>400</b>-<b>1800</b>, which list additional possible tool error outputs for different functional areas (e.g., non-text content, image maps, captions, etc.) of the WebKing code inspection service. Each of the additional exemplary defect classification mapping profiles <b>400</b>-<b>1800</b> are derived and used in a similar manner to exemplary defect classification mapping profile <b>300</b>. However, as explained above, each of the exemplary defect classification mapping profiles <b>400</b>-<b>1800</b> are for different functional areas of the WebKing code inspection service. As such, each of the exemplary defect classification mapping profiles <b>400</b>-<b>1800</b> may have different possible tool error outputs <b>310</b> (e.g., error texts). As each of the additional exemplary defect classification mapping profiles <b>400</b>-<b>1800</b> are derived and used in a similar manner to exemplary defect classification mapping profile <b>300</b>, a further description of <figref idref="DRAWINGS">FIGS. 4-18</figref> is not necessary for those of ordinary skill in the art to practice the invention.
0082<figref idref="DRAWINGS">FIG. 19</figref> illustrates an additional exemplary defect classification mapping profile <b>1900</b> for the Purify Plus code inspection service. The exemplary defect classification mapping profile <b>1900</b> is derived and used in a similar manner to exemplary defect classification mapping profiles <b>300</b>-<b>1800</b>. However, as explained above, exemplary defect classification mapping profile <b>1900</b> is for the Purify Plus code inspection service. As such, exemplary defect classification mapping profile <b>1900</b> may have different possible tool error outputs <b>310</b>. Additionally, exemplary defect classification mapping profile <b>1900</b> includes a separate column for trigger, as the trigger varies depending on the tool error output <b>310</b>. As exemplary defect classification mapping profile <b>1900</b> is derived and used in a similar manner to exemplary defect classification mapping profiles <b>300</b>-<b>1800</b>, a further description of <figref idref="DRAWINGS">FIG. 19</figref> is not necessary for those of ordinary skill in the art to practice the invention.
0083<figref idref="DRAWINGS">FIG. 20</figref> illustrates an additional exemplary defect classification mapping profile <b>2000</b> for the ABAP Code Optimizer code inspection service. The exemplary defect classification mapping profile <b>2000</b> is derived and used in a similar manner to exemplary defect classification mapping profiles <b>300</b>-<b>1900</b>. However, as explained above, exemplary defect classification mapping profile <b>2000</b> is for the ABAP Code Optimizer code inspection service. As such, exemplary defect classification mapping profile <b>2000</b> may have different possible tool error outputs <b>310</b>. Additionally, exemplary defect classification mapping profile <b>2000</b> includes additional classifications (e.g., category and sub-category). As exemplary defect classification mapping profile <b>2000</b> is derived and used in a similar manner to exemplary defect classification mapping profiles <b>300</b>-<b>1900</b>, a further description of <figref idref="DRAWINGS">FIG. 20</figref> is not necessary for those of ordinary skill in the art to practice the invention.
0084<figref idref="DRAWINGS">FIG. 21</figref> illustrates an additional exemplary defect classification mapping profile <b>2100</b> for of the APPScan code inspection service. The exemplary defect classification mapping profile <b>2100</b> is derived and used in a similar manner to exemplary defect classification mapping profiles <b>300</b>-<b>2000</b>. However, as explained above, exemplary defect classification mapping profile <b>2100</b> is for the APPScan code inspection service. As such, exemplary defect classification mapping profile <b>2100</b> may have different possible tool error outputs <b>310</b>. As exemplary defect classification mapping profile <b>2100</b> is derived and used in a similar manner to exemplary defect classification mapping profiles <b>300</b>-<b>2000</b>, a further description of <figref idref="DRAWINGS">FIG. 21</figref> is not necessary for those of ordinary skill in the art to practice the invention.
0085<figref idref="DRAWINGS">FIGS. 22-41</figref> illustrate exemplary defect classification mapping profiles <b>2200</b>-<b>4100</b>, which list possible tool error outputs for the CAST code inspection service. Each of the exemplary defect classification mapping profiles <b>2200</b>-<b>4100</b> are derived and used in a similar manner to exemplary defect classification mapping profiles <b>300</b>-<b>2100</b>. However, each of the exemplary defect classification mapping profiles <b>2200</b>-<b>4100</b> is for the CAST code inspection service. As such, for example as shown in <figref idref="DRAWINGS">FIG. 22</figref>, each of the exemplary defect classification mapping profiles <b>2200</b>-<b>4100</b> may have different possible tool error outputs <b>310</b>. As each of the exemplary defect classification mapping profiles <b>2200</b>-<b>4100</b> are derived and used in a similar manner to exemplary defect classification mapping profiles <b>300</b>-<b>2100</b>, a further description of <figref idref="DRAWINGS">FIGS. 22-41</figref> is not necessary for those of ordinary skill in the art to practice the invention.
0086As can be observed from the exemplary defect classification mapping profiles <b>300</b>-<b>4100</b> and as discussed further below, the present invention is operable to translate the outputs of the different code inspection services to one or more standardized metrics, e.g., in accordance with a common schema. That is, for each of the different possible code error outputs of the different code inspection services, as shown in <figref idref="DRAWINGS">FIGS. 3-41</figref>, the DAS/DRM defect profiles <b>300</b>-<b>4100</b> indicate metrics, e.g., severity, target, trigger, impact, type and qualifier, in accordance with the common schema. In this way, the classification mapping of the present invention enables defect analysis reporting, e.g., of the metrics, of defects identified, for example, from different code inspection tools.
Exemplary Reports
0087<figref idref="DRAWINGS">FIGS. 42-59</figref> illustrate exemplary reports (or components of a report) in accordance with aspects of the invention. However, these exemplary reports should not be considered as exhaustive of all reports contemplated by the invention. That is, the invention contemplates that the report generation tool <b>40</b> may generate other reports. Additionally, while <figref idref="DRAWINGS">FIGS. 44-58</figref> illustrate exemplary reports as histograms, the invention contemplates other formats for the reports. As such, the exemplary reports (or components of reports) of <figref idref="DRAWINGS">FIGS. 42-59</figref> should not be construed as limiting the present invention. In embodiments, the present invention is operable to transform the output <b>215</b> of selected code inspection services to one or more reports that include defect analysis metrics.
0088As discussed above, in embodiments, for example, the report generation tool <b>40</b> may provide a report containing an analysis or assessment. The assessment may include for each of technical quality, security, memory and accessibility, a rating of results against expectation and error prone area identification with implications. In embodiments, the present invention is operable to manipulate, e.g., map, the output of the selected code inspection services using the selected defect classification mapping profile(s) <b>217</b> to generate the report that includes defect analysis metrics, e.g., using the report generation tool <b>40</b> (shown in <figref idref="DRAWINGS">FIG. 1</figref>). <figref idref="DRAWINGS">FIG. 42</figref> illustrates an exemplary assessment <b>4200</b> including a rating of results <b>4205</b> against expectation <b>4210</b> for each of technical quality, security, memory and accessibility. <figref idref="DRAWINGS">FIG. 43</figref> illustrates an exemplary quantification of error types (e.g., technical quality, security, memory and accessibility) in terms of KLOC (thousand of lines of code) and percentage of total errors.
0089<figref idref="DRAWINGS">FIG. 44</figref> illustrates an exemplary histogram <b>4400</b> of defects found by tool error category, and implications. In accordance with aspects of the invention, the report generation tool <b>40</b> may generate a histogram, e.g., exemplary histogram <b>4400</b> of defects found by tool error category, and implications, as a report or as a component of a report. Additionally, in embodiments, the histogram <b>4400</b> may indicate subcategories, if they are defined. More specifically, <figref idref="DRAWINGS">FIG. 44</figref> illustrates a quantification of accessibility defects found using a particular code inspection service for two rules and/or industry standards (e.g., “Standard/Rule 1” and “Standard/Rule 2”). Accessibility errors, for example, may relate to a standard of rules for handicapped, disabled or senior users. The different possible defects (e.g., frames, forms, captions, etc.) are listed in the table key <b>4410</b> and identified by, e.g., different pattern and/or shades. Thus, as can be observed in exemplary histogram <b>4400</b>, with Standard/Rule 1, approximately fifty-three errors are detected and with Standard/Rule 2, approximately fifteen errors are detected.
0090While exemplary histogram <b>4400</b> quantifies defects found by tool error category, and implication, this information is limited to what an automated tool can look for. Additionally, exemplary histogram <b>4400</b> may not allow for any conclusions (e.g., future planning) as no particular defect significantly stands out more than any other defect.
0091<figref idref="DRAWINGS">FIG. 45</figref> illustrates an exemplary histogram of defects by severity <b>4500</b>. More specifically, <figref idref="DRAWINGS">FIG. 45</figref> illustrates the errors detected as shown in <figref idref="DRAWINGS">FIG. 44</figref>, however, the errors are now quantified by severity level, e.g., severity 1, 2 or 3, (as determined by the defect classification mapping tool <b>35</b>). In accordance with aspects of the invention, by quantifying (and presenting in a report) the detected errors identified by severity level, for example, as illustrated in <figref idref="DRAWINGS">FIG. 45</figref>, the present invention may be used to identify opportunities, e.g., to prevent the injection of defects, as discussed further below.
0092<figref idref="DRAWINGS">FIG. 46</figref> illustrates an exemplary histogram of defects <b>4600</b> by DRM artifact type (e.g., checking, algorithm/method, or assignment/initialization) and qualifier (e.g., incorrect or missing) in accordance with aspects of the invention. More specifically, <figref idref="DRAWINGS">FIG. 46</figref> illustrates the errors detected as shown in <figref idref="DRAWINGS">FIG. 44</figref>, however, the same errors are now quantified by DRM artifact type and qualifier, (as determined by the defect classification mapping tool <b>35</b>).
0093In accordance with aspects of the invention, by quantifying (and presenting in a report) the detected errors identified by DRM artifact type and qualifier, for example, as illustrated in <figref idref="DRAWINGS">FIG. 46</figref>, the present invention may be used to identify opportunities, e.g., to prevent the injection of defects. With an understanding of how past defects (as detected by the code inspection tools) were injected into the software code lifecycle, an organization may discover opportunities for preventing the injection of future defects. For example, as shown in <figref idref="DRAWINGS">FIG. 46</figref>, a majority of the algorithm/method type defects have a “missing” defect qualifier. Conversely, with the example of <figref idref="DRAWINGS">FIG. 46</figref>, a majority of the checking type defects have an “incorrect” defect qualifier. In accordance with aspects of the invention, this information may be used to discover opportunities for preventing the injection of future defects, e.g., adjusting staffing levels and/or review processes.
0094<figref idref="DRAWINGS">FIG. 47</figref> illustrates an exemplary illustration of table <b>4700</b> of defect artifact types mapped to a process point when those defects are injected. In embodiments, table <b>4700</b> may be used to identify defect prevention opportunities. As shown in <figref idref="DRAWINGS">FIG. 47</figref>, table <b>4700</b> includes column <b>4705</b> listing the generic process areas in the software development life cycle when particular defects may be injected. As illustrated in <figref idref="DRAWINGS">FIG. 4700</figref>, the lowest process area, “code,” is later in the life cycle and the highest process area, “high level requirements,” is earlier in the life cycle. Table <b>4700</b> additionally includes qualifier column <b>4710</b> indicating a defect qualifier (e.g., missing or incorrect) and a type column <b>4715</b> indicating a defect type (e.g., relationship, checking, etc.).
0095Table <b>4700</b> indicates earlier process areas <b>4720</b> and later process areas <b>4725</b>. Earlier process areas <b>4720</b> include defects that are only found by a user evaluating function in relatively sophisticated ways. As such, an automated code inspection tool would not discover these types of defects. In contrast, later process areas <b>4725</b> include defects uncovered using an automated code inspection tool. In accordance with aspects of the invention, in embodiments, the report generation tool is operable to map defects by artifact type, qualifier and/or process area.
0096With an understanding of how past defects (as detected by the code inspection tools) were injected into the software code lifecycle, an organization may discover opportunities for preventing the injection of further defects. For example, “missing algorithms” and “missing checking” may each indicate weaknesses existed in the low level (or detailed) requirements development and/or process. Additionally, for example “incorrect assignments” and “incorrect checking” indicate coding oversights. “Missing assignments” indicates coding oversights as well. Static testing methods, such as code inspection services, unit testing and/or code inspections, could be used to remove such coding oversights earlier in the life cycle (thus, reducing costs).
0097<figref idref="DRAWINGS">FIG. 48</figref> illustrates an exemplary histogram <b>4800</b> of memory defects found using a particular code inspection service (e.g., Purify Plus) by severity level. As shown in <figref idref="DRAWINGS">FIG. 48</figref>, histogram <b>4800</b> quantifies occurrences of each of the possible tool error outputs <b>310</b> for the Purify Plus code inspection tool. Moreover, histogram <b>4800</b> indicates the number of defects by severity level. As can be observed, with exemplary histogram <b>4800</b> all of the errors are “Severity 1.”
0098<figref idref="DRAWINGS">FIG. 49</figref> illustrates an exemplary histogram of memory defects <b>4900</b> by DRM artifact type (e.g., checking, algorithm/method, or assignment/initialization) and qualifier (e.g., incorrect or missing) in accordance with aspects of the invention. <figref idref="DRAWINGS">FIG. 49</figref> is similar to <figref idref="DRAWINGS">FIG. 46</figref>, described above. As such, further description of <figref idref="DRAWINGS">FIG. 49</figref> is not necessary for those of skill in the art to practice the present invention, but for further elucidation, pertinent portions of the figures are discussed herein. In accordance with aspects of the invention, by quantifying (and presenting in a report) the detected errors identified by DRM artifact type and qualifier, for example, as illustrated in <figref idref="DRAWINGS">FIG. 49</figref>, the present invention may be used to identify opportunities, e.g., to prevent the injection of defects. With an understanding of how past defects (as detected by the code inspection tools) were injected into the software code lifecycle, an organization may discover opportunities for preventing the injection of future defects. For example, as shown in <figref idref="DRAWINGS">FIG. 49</figref>, all of the defects have a “missing” defect qualifier. In accordance with aspects of the invention, this information may be used to discover opportunities for preventing the injection of future defects, e.g., adjusting staffing levels and/or review processes.
0099<figref idref="DRAWINGS">FIG. 50</figref> illustrates an exemplary histogram <b>5000</b> of defects found by tool error category, and implications. In accordance with aspects of the invention, the report generation tool <b>40</b> may generate a histogram, e.g., exemplary histogram <b>5000</b> of defects found by tool error category, and implications, as a report or as a component of a report. Additionally, in embodiments, the histogram <b>5000</b> may indicate defect subcategories, if they are defined (for example, as listed in the table key <b>5010</b> and identified by, e.g., different pattern and/or shades). More specifically, <figref idref="DRAWINGS">FIG. 50</figref> illustrates a quantification of security defects found using a particular code inspection service. As shown in <figref idref="DRAWINGS">FIG. 50</figref>, the most frequent security defects (e.g., as determined by a code inspection service) are “Information Disclosure” security defects. Additionally, for each defect type, exemplary histogram <b>5000</b> indicates security defect subcategories.
0100<figref idref="DRAWINGS">FIG. 51</figref> illustrates an exemplary histogram of security defects by severity <b>5100</b>. More specifically, <figref idref="DRAWINGS">FIG. 51</figref> illustrates the errors detected as shown in <figref idref="DRAWINGS">FIG. 50</figref>, however, the errors are now quantified by severity level, e.g., severity 1, 2, 3 or 4 (as determined by the defect classification mapping tool <b>35</b>). In accordance with aspects of the invention, by quantifying (and presenting in a report) the detected errors identified by severity level, for example, as illustrated in <figref idref="DRAWINGS">FIG. 51</figref>, the present invention may be used to identify opportunities, e.g., to prevent the injection of defects.
0101<figref idref="DRAWINGS">FIG. 52</figref> illustrates an exemplary histogram of security defects by DRM artifact type (e.g., checking, algorithm/method, or assignment/initialization, etc.) and qualifier (e.g., incorrect or missing) in accordance with aspects of the invention. <figref idref="DRAWINGS">FIG. 52</figref> is similar to <figref idref="DRAWINGS">FIGS. 46 and 49</figref>, described above. As such, further description of <figref idref="DRAWINGS">FIG. 52</figref> is not necessary for those of skill in the art to practice the present invention, but for further elucidation, pertinent portions of the figures are discussed herein. In accordance with aspects of the invention, by quantifying (and presenting in a report) the detected security errors identified by DRM artifact type and qualifier, for example, as illustrated in <figref idref="DRAWINGS">FIG. 52</figref>, the present invention may be used to identify opportunities, e.g., to prevent the injection of defects. For example, as shown in <figref idref="DRAWINGS">FIG. 52</figref>, most of the security defects have a “missing” defect qualifier. In accordance with aspects of the invention, this information may be used to discover opportunities for preventing the injection of future security defects, e.g., adjusting staffing levels and/or review processes.
0102<figref idref="DRAWINGS">FIGS. 53-55</figref> illustrate exemplary histogram <b>5300</b> of technical quality defects found by tool error category, and implications, exemplary histogram <b>5400</b> of technical quality defects by severity and exemplary histogram of technical quality defects by DRM artifact type (e.g., checking, algorithm/method, or assignment/initialization, etc.) and qualifier (e.g., incorrect or missing) in accordance with aspects of the invention As <figref idref="DRAWINGS">FIGS. 53-55</figref> are similar to <figref idref="DRAWINGS">FIGS. 50-52</figref>, described above, a further description of <figref idref="DRAWINGS">FIGS. 53-55</figref> is not necessary for those of skill in the art to practice the invention.
0103<figref idref="DRAWINGS">FIG. 56</figref> illustrates an exemplary summary metrics histogram <b>5600</b> indicating a quantification of defect types. Additionally, histogram <b>5600</b> indicates, for each defect type, (e.g., transferability, security, etc.), the number of errors for each severity level (e.g., “Severity 1,” “Severity 2,” etc.), as indicated by key <b>5610</b>.
0104<figref idref="DRAWINGS">FIG. 57</figref> illustrates an exemplary summary metrics histogram <b>5700</b> indicating a quantification of defects in the four analysis areas (e.g., technical quality, security, accessibility and memory) for the different stages of the software development life cycle (e.g., high level requirements, detailed design, etc.), as indicated by key <b>5710</b>. <figref idref="DRAWINGS">FIG. 58</figref> illustrates an exemplary summary metrics histogram <b>5800</b> indicating a quantification of defects as a percentage of total defects in the four analysis areas (e.g., technical quality, security, accessibility and memory) for the different stages of the software development life cycle (e.g., high level requirements, detailed design, etc.), as indicated by key <b>5710</b>.
0105<figref idref="DRAWINGS">FIG. 59</figref> illustrates a trigger summary <b>5900</b> in accordance with aspects of the invention. As shown in <figref idref="DRAWINGS">FIG. 59</figref>, the trigger summary <b>5900</b> includes an analysis area column <b>5905</b> indicating the analysis area (e.g., accessibility, memory, technical quality, and security). Additionally, the trigger summary <b>5900</b> includes a trigger column <b>5910</b> listing the detected defect triggers (e.g., as determined from the code inspection service) and a severity level column <b>5915</b> listing the severities for each of the defect triggers (e.g., as determined by the defect classification mapping tool <b>35</b>). The trigger summary <b>5900</b> also includes a frequency column <b>5920</b> which indicates a quantification of detected code defects by trigger and severity.
Flow Diagram
0106<figref idref="DRAWINGS">FIG. 60</figref> shows an exemplary flow for performing aspects of the present invention. The steps of <figref idref="DRAWINGS">FIG. 60</figref> may be implemented in the environment of <figref idref="DRAWINGS">FIG. 1</figref>, for example. The flow diagram may equally represent a high-level block diagram or a swim-lane diagram of the invention. The flowchart and/or block diagram in <figref idref="DRAWINGS">FIG. 60</figref> illustrates the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart, block diagram or swim-lane diagram may represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figure. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. Each block of each flowchart, and combinations of the flowchart illustration can be implemented by special purpose hardware-based systems that perform the specified functions or acts, or combinations of special purpose hardware and computer instructions and/or software, as described above. Moreover, the steps of the flow diagram may be implemented and executed from either a server, in a client server relationship, or they may run on a user workstation with operative information conveyed to the user workstation. In an embodiment, the software elements include firmware, resident software, microcode, etc.
0107In embodiments, a service provider, such as a Solution Integrator, could offer to perform the processes described herein. In this case, the service provider can create, maintain, deploy, support, etc., the computer infrastructure that performs the process steps of the invention for one or more customers. These customers may be, for example, any business that uses technology. In return, the service provider can receive payment from the customer(s) under a subscription and/or fee agreement and/or the service provider can receive payment from the sale of advertising content to one or more third parties.
0108Furthermore, the invention can take the form of a computer program product accessible from a computer-usable or computer-readable medium providing program code for use by or in connection with a computer or any instruction execution system. The software and/or computer program product can be implemented in the environment of <figref idref="DRAWINGS">FIG. 1</figref>. For the purposes of this description, a computer-usable or computer readable medium can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. The medium can be an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system (or apparatus or device) or a propagation medium. Examples of a computer-readable storage medium include a semiconductor or solid state memory, magnetic tape, a removable computer diskette, a random access memory (RAM), a read-only memory (ROM), a rigid magnetic disk and an optical disk. Current examples of optical disks include compact disk-read only memory (CD-ROM), compact disc-read/write (CD-R/W) and DVD.
0109As shown in <figref idref="DRAWINGS">FIG. 6000</figref>, at step <b>6005</b>, an error output receiving tool receives the code inspection service tool error output determined from testing, e.g., an organization's code. At step <b>6010</b>, the selection tool selects one or more appropriate defect classification mapping profiles based on which code inspection service(s) was (or were) utilized to test code. For example, if a WebKing automated code inspection service has been utilized, the present invention accesses the WebKing defect classification mapping profile(s).
0110At step <b>6015</b>, the defect classification mapping tool maps errors of the tool error output to the selected one or more defect classification mapping profiles. For example, the defect classification mapping tool may quantify the occurrences of each possible tool error outputs for each of the selected code inspection services and map each of the error outputs to its respective classifications (e.g., target, trigger, impact, type, qualifier and severity level, amongst other classifications) using the appropriate defect classification mapping profile defect. At step <b>6020</b>, the report generation tool generates one or more reports based on the mapping of the tool error output to the selected one or more defect classification mapping profiles, for example, a report containing, e.g., defect analysis metrics.
0111The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” and/or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and/or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and/or groups thereof.
0112The corresponding structures, materials, acts, and equivalents of all means or step plus function elements in the claims, if applicable, are intended to include any structure, material, or act for performing the function in combination with other claimed elements as specifically claimed. The description of the present invention has been presented for purposes of illustration and description, but is not intended to be exhaustive or limited to the invention in the form disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the invention. The embodiment was chosen and described in order to best explain the principals of the invention and the practical application, and to enable others of ordinary skill in the art to understand the invention for various embodiments with various modifications as are suited to the particular use contemplated. Accordingly, while the invention has been described in terms of embodiments, those of skill in the art will recognize that the invention can be practiced with modifications and in the spirit and scope of the appended claims.
Contents5
53 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8935680B2 | Cited by | United States of America | Applicant |
| US2015278526A1 | Cited by | United States of America | Pre-grant |
| US10275333B2 | Cited by | United States of America | Search report |
| US2017177591A1 | Cited by | United States of America | Search report |
| US2013014093A1 | Cited by | United States of America | Pre-grant |
| US9626432B2 | Cited by | United States of America | Search report |
| US10679295B1 | Cited by | United States of America | Search report |
| US2015363292A1 | Cited by | United States of America | Pre-grant |
| US10339170B2 | Cited by | United States of America | Search report |
| US2013061201A1 | Cited by | United States of America | Pre-grant |
| CN113168472A | Cited by | China | Search report |
| US2015261661A1 | Cited by | United States of America | Pre-grant |
| US11244269B1 | Cited by | United States of America | Search report |
| US9298584B2 | Cited by | United States of America | Search report |
| US2019129828A1 | Cited by | United States of America | Search report |
| US2019129828A1 | Cited by | United States of America | Search report |
| US2019266184A1 | Cited by | United States of America | Search report |
| WO2026056270A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US2017177591A1 | Cited by | United States of America | Pre-grant |
| US2015073773A1 | Cited by | United States of America | Pre-grant |
| US2019129828A1 | Cited by | United States of America | Search report |
| US8875110B2 | Cited by | United States of America | Search report |
| CN115437923A | Cited by | China | Search report |
| US10891325B2 | Cited by | United States of America | Search report |
| US2001052108A1 | Cites | United States of America | Pre-grant |
| US2002078401A1 | Cites | United States of America | Pre-grant |
| US2002188414A1 | Cites | United States of America | Pre-grant |
| US2003018952A1 | Cites | United States of America | Pre-grant |
| US2003033191A1 | Cites | United States of America | Pre-grant |
| US2003058277A1 | Cites | United States of America | Pre-grant |
| US2003070157A1 | Cites | United States of America | Pre-grant |
| US2003196190A1 | Cites | United States of America | Pre-grant |
| US2004205727A1 | Cites | United States of America | Pre-grant |
| US2004267814A1 | Cites | United States of America | Pre-grant |
| US2005071807A1 | Cites | United States of America | Pre-grant |
| US2005102654A1 | Cites | United States of America | Pre-grant |
| US2005114828A1 | Cites | United States of America | Pre-grant |
| US2005144529A1 | Cites | United States of America | Pre-grant |
| US2005209866A1 | Cites | United States of America | Pre-grant |
| US2005283751A1 | Cites | United States of America | Pre-grant |
| US2006047617A1 | Cites | United States of America | Pre-grant |
| US2006248504A1 | Cites | United States of America | Pre-grant |
| US2006251073A1 | Cites | United States of America | Pre-grant |
| US2006265188A1 | Cites | United States of America | Pre-grant |
| US2007100712A1 | Cites | United States of America | Pre-grant |
| US2007112879A1 | Cites | United States of America | Pre-grant |
| US2007174023A1 | Cites | United States of America | Pre-grant |
| US2007234294A1 | Cites | United States of America | Pre-grant |
| US2007283325A1 | Cites | United States of America | Pre-grant |
| US2007283417A1 | Cites | United States of America | Pre-grant |
| US2007300204A1 | Cites | United States of America | Pre-grant |
| US2008010543A1 | Cites | United States of America | Pre-grant |
| US2008052707A1 | Cites | United States of America | Pre-grant |
| US2008072328A1 | Cites | United States of America | Pre-grant |
| US2008092108A1 | Cites | United States of America | Pre-grant |
| US2008092120A1 | Cites | United States of America | Pre-grant |
| US2008104096A1 | Cites | United States of America | Pre-grant |
| US2008162995A1 | Cites | United States of America | Pre-grant |
| US2008178145A1 | Cites | United States of America | Pre-grant |
| US2008201611A1 | Cites | United States of America | Pre-grant |
| US2008201612A1 | Cites | United States of America | Pre-grant |
| US2008255693A1 | Cites | United States of America | Pre-grant |
| US2009070734A1 | Cites | United States of America | Pre-grant |
| US2010005444A1 | Cites | United States of America | Pre-grant |
| US2010145929A1 | Cites | United States of America | Pre-grant |
| US2010211957A1 | Cites | United States of America | Pre-grant |
| US2010275263A1 | Cites | United States of America | Pre-grant |
| US2010332274A1 | Cites | United States of America | Pre-grant |
| US2011296371A1 | Cites | United States of America | Pre-grant |
| US2012017195A1 | Cites | United States of America | Pre-grant |
| US2012053986A1 | Cites | United States of America | Pre-grant |
| US5539652A | Cites | United States of America | Pre-grant |
| US5905856A | Cites | United States of America | Pre-grant |
| US6332211B1 | Cites | United States of America | Pre-grant |
| US6442748B1 | Cites | United States of America | Pre-grant |
| US6456506B1 | Cites | United States of America | Pre-grant |
| US6477471B1 | Cites | United States of America | Pre-grant |
| US6519763B1 | Cites | United States of America | Pre-grant |
| US6546506B1 | Cites | United States of America | Pre-grant |
| US6601233B1 | Cites | United States of America | Pre-grant |
| US6725399B1 | Cites | United States of America | Pre-grant |
| US6889167B2 | Cites | United States of America | Pre-grant |
| US6901535B2 | Cites | United States of America | Pre-grant |
| US6988055B1 | Cites | United States of America | Pre-grant |
| US7200775B1 | Cites | United States of America | Pre-grant |
| US7231549B1 | Cites | United States of America | Pre-grant |
| US7334166B1 | Cites | United States of America | Pre-grant |
| US7451009B2 | Cites | United States of America | Pre-grant |
| US7788647B2 | Cites | United States of America | Pre-grant |
| US7809520B2 | Cites | United States of America | Pre-grant |
| US7861226B1 | Cites | United States of America | Pre-grant |
| US7886272B1 | Cites | United States of America | Pre-grant |
| US7917897B2 | Cites | United States of America | Pre-grant |
| US7984304B1 | Cites | United States of America | Pre-grant |
| US8191044B1 | Cites | United States of America | Pre-grant |
| Title: A tool to support perspective based approach to software code inspection, author: Chan, Lipo, dated: 2005, source: IEEE | Non-patent | – | Pre-grant |
10 members in 1 office; this record represents the family
Members10
| Document | Office | Kind | |
|---|---|---|---|
| US2011067006A1 | United States of America | A1 | |
| US8527955B2 | United States of America | B2 | |
| US2013283239A1 | United States of America | A1 | |
| US8924936B2 | United States of America | B2 | |
| US2015067649A1 | United States of America | A1 | |
| US9176844B2 | United States of America | B2 | |
| US2015378866A1 | United States of America | A1 | |
| US9442821B2 | United States of America | B2 | |
| US2016328313A1 | United States of America | A1 | |
| US9753838B2 | United States of America | B2 |
78 transactions on the USPTO file
Allowed after 1 non-final rejection.
- Non-final rejections
- 1
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Expire PatentEXP. | EXP. | |
| Maintenance Fee Reminder MailedREM. | REM. | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Email NotificationEML_NTR | EML_NTR | |
| Printer Rush- No mailingTCPB | TCPB | |
| Mail Examiner's AmendmentMEX.A | MEX.A | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Email NotificationEML_NTR | EML_NTR | |
| Printer Rush- No mailingTCPB | TCPB | |
| Mail Miscellaneous Communication to ApplicantMM327 | MM327 | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Correspondence Address ChangeC.AD | C.AD | |
| Miscellaneous Communication to Applicant - No Action CountM327 | M327 | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Email NotificationEML_NTR | EML_NTR | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Email NotificationEML_NTR | EML_NTR | |
| Filing Receipt - UpdatedFLRCPT.U | FLRCPT.U | |
| Sent to Classification ContractorPGPC | PGPC | |
| Additional Application Filing FeesADDFLFEE | ADDFLFEE | |
| A statement by one or more inventors satisfying the requirement under 35 USC 115, Oath of the ApplicOATHDECL | OATHDECL | |
| Applicant has submitted new drawings to correct Corrected Papers problemsCORRDRW | CORRDRW | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTR | EML_NTR | |
| Email NotificationEML_NTF | EML_NTF | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Cleared by OIPE CSRL194 | L194 | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Fee paymentFPAY | FPAY | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication
- 20110067006
- Application
- 12558274
Titles
- English
- SYSTEM AND METHOD TO CLASSIFY AUTOMATED CODE INSPECTION SERVICES DEFECT OUTPUT FOR DEFECT ANALYSIS
Patent term adjustment
- A delay
- +725 daysthe office missed an examination deadline
- B delay
- +357 dayspendency past three years
- Overlap
- −55 daysdelays counted once
- Applicant delay
- −49 days
- Net adjustment
- 978 days
Classification
- CPC, 3
- G06F11/3604
- G06F11/3668
- G06F9/44589
- IPC, 1
- G06F11 36