industry news
Subscribe Now

PRQA Introduces Enhanced Code Compliance Module To Improve Security of Automotive and Internet of Things Software at SAE World Congress April 12-14, 2016

Detroit, MI, April 11th, 2016 – PRQA, a leader and pioneer in automated software coding governance solutions for embedded application development, today announced updates to their CERT® C Compliance Module and source code analytics system atSAE 2016 World CongressApril 12-14 in Detroit, MI. Cobo Center booth 508 #SAECongress.

The Connected Car is one of the most visible examples of how the Internet of Things (IoT) has evolved. Also, it highlights the importance of security in a world that is increasingly dependent on software. As developers produce more and more software to power new IoT products, they introduce new risks and bring to market devices vulnerable to security attacks. Cutting-edge hackers are acutely aware that many of the security procedures and applications in use today have been designed to defend against attacks on personal computers, not mobile and embedded systems.

A majority of security vulnerabilities are a result of coding errors that go undetected in the development stage. Several recent studies have identified coding issues as the primary cause of exploitable security vulnerabilities. Carnegie Mellon’s Computer Emergency Response Team (CERT) found that 64% of vulnerabilities in the CERT National Vulnerability Database were the result of programming errors.

PRQA, a founding member of the MISRA C and C++ committees and noted in the industry for its MISRA compliance capabilities, which are used by major automotive OEMs and Tier 1 suppliers such as Robert Bosch, Valeo, TRW Automotive, Ford Motors, Visteon Corporation, Autoliv and Magna, is continually enhancing its security capabilities, including CERT® C compliance, to stay ahead of a rapidly evolving threat landscape.

“PRQA continues to improve our security capabilities because we understand the complexity, additional cost and burden of meeting the enormous security challenges that our Automotive and IoT customers today face,” said Paul Blundell, ’PRQA’s CEO. “With the PRQA static analysis platform, our customers can detect and correct critical software defects to ensure reliable, safe and secure software and build trust into connected devices in a cost effective and efficient manner to avoid security concerns and capitalize on the full potential of the exploding IoT markets.”

The enhanced CERT® C Compliance Module (CERTCCM) is designed to enforce compliance with the CERT® C coding standard in conjunction with the PRQA’s QA·C static analyzer. The analyzer can rapidly examine millions of lines of source code and can detect most of the statically enforceable conditions identified in the CERT® C guidelines (as well as many others). CERTCCM configures QA?C to identify issues that are specific to those guidelines, and provides a cross-reference between the standard QA?C warning message(s) and the corresponding CERT® C guideline.

Robert Seacord, founder of the Secure Coding Institute, commented: “PRQA’s QA·C analyzer is effective at discovering violations of The CERT® C Coding Standard that were not discovered through 20 years of testing or by other static analysis tools”. And he continues, “Overall, the QA·C analyzer is an effective tool for eliminating secure coding flaws that can easily lead to software vulnerabilities.”

With recently improved security capabilities, PRQA is now complementing MISRA compliance with CERT® C and CWE, enabling compliance enforcement that can be applied to both new and legacy code increasing code reusability and decreasing time to market.

With decades of software analysis innovation and expertise, PRQA has become the leader in source code analysis solutions for embedded software development. The company’s static analyzers, compliance modules, and management dashboards work together, as an easy to use enterprise-grade source code analytics system. This system enables organizations to test application code with unsurpassed depth and accuracy, enabling customers to manage global software development efforts and deliver reliable, safe and secure embedded software for everything from networking products and medical devices to railway systems, industrial automation, and the Internet of Things.

About PRQA

Detect, enforce and measure

Since 1985, PRQA has pioneered software coding governance in the automotive, aerospace, transport, finance, medical device and energy industries. Supporting both small start-ups and globally recognized brands, we provide sophisticated code analysis, robust defect detection and enforcement of both bespoke and industry coding standards through functional integrity and application security/safety.

PRQA’s industry-leading solutions, QA·C, QA·C++, QA·J and QA·C# offer the most meticulous static analysis of commonly used programming languages. Innovations such as multi-threading and resource analysis (MTR) complement this with refined multi-thread inspection of code streams.  Used locally or centrally deployed via the Quality Management System QA·Verify, we enable early find/fix at the desktop and on the server side complete control, visibility and history to the decision maker.

ISO 9001 and TickIT certified.

www.programmingresearch.com


Leave a Reply

featured blogs
Apr 26, 2024
LEGO ® is the world's most famous toy brand. The experience of playing with these toys has endured over the years because of the innumerable possibilities they allow us: from simple textbook models to wherever our imagination might take us. We have always been driven by ...
Apr 26, 2024
Biological-inspired developments result in LEDs that are 55% brighter, but 55% brighter than what?...
Apr 25, 2024
See how the UCIe protocol creates multi-die chips by connecting chiplets from different vendors and nodes, and learn about the role of IP and specifications.The post Want to Mix and Match Dies in a Single Package? UCIe Can Get You There appeared first on Chip Design....

featured video

How MediaTek Optimizes SI Design with Cadence Optimality Explorer and Clarity 3D Solver

Sponsored by Cadence Design Systems

In the era of 5G/6G communication, signal integrity (SI) design considerations are important in high-speed interface design. MediaTek’s design process usually relies on human intuition, but with Cadence’s Optimality Intelligent System Explorer and Clarity 3D Solver, they’ve increased design productivity by 75X. The Optimality Explorer’s AI technology not only improves productivity, but also provides helpful insights and answers.

Learn how MediaTek uses Cadence tools in SI design

featured paper

Designing Robust 5G Power Amplifiers for the Real World

Sponsored by Keysight

Simulating 5G power amplifier (PA) designs at the component and system levels with authentic modulation and high-fidelity behavioral models increases predictability, lowers risk, and shrinks schedules. Simulation software enables multi-technology layout and multi-domain analysis, evaluating the impacts of 5G PA design choices while delivering accurate results in a single virtual workspace. This application note delves into how authentic modulation enhances predictability and performance in 5G millimeter-wave systems.

Download now to revolutionize your design process.

featured chalk talk

Switch to Simple with Klippon Relay
In this episode of Chalk Talk, Amelia Dalton and Lars Hohmeier from Weidmüller explore the what, where, and how of Weidmüller's extensive portfolio of Klippon relays. They investigate the pros and cons of mechanical relays, the benefits that the Klippon universal range of relays brings to the table, and how Weidmüller's digital selection guide can help you choose the best relay solution for your next design.
Sep 26, 2023
26,871 views