← Back to NASA Technology Projects

Static Detection of Bugs in Embedded Software using Lightweight Verification, Phase I

Completed

Description

Validating software is a critical step in developing high confidence systems. Typical software development practices are not acceptable in systems where failure leads to loss of life or other high costs. New software development tools are needed to radically reduce defect rates and enable the high levels of confidence required for safety- and security-critical systems. Lightweight verification techniques have proven themselves effective in finding defects in large software systems by balancing rigor with scalability and usability. Lightweight verification techniques do not exhaustively check software, but they can find defects in systems that are too large for more rigorous analysis techniques, and are fast becoming an essential tool for software developers. The techniques generally fail to address key sources of problems specific to embedded systems: paths due to asynchronous transfer of control or context switches between tasks are not considered; assembly language components are ignored; it is hard to detect violations of domain-specific rules. We propose to extend and adapt our static analysis technology to make it capable of addressing these problems. We will exploit our existing connections with NASA facilities to gain help validating our approach and to ensure that the solution we propose is responsive to NASA's unique needs.

Benefits

Potential NASA Commercial Applications: Lightweight verification tools such as CodeSonar are becoming increasingly popular in many industrial sectors, especially those concerned with developing high-confidence real-time embedded software. This includes communications, military/aerospace, medical devices, automotive, finance, security, and others. If successful, the technology we propose to develop will provide the capability to find more serious flaws in such software than current approaches, thereby cutting development costs and increasing code quality.

Details

Technology areaSoftware, Modeling, Simulation, and Information Processing > Software Development, Engineering, and Integrity > V&V of Software systems
ProgramSmall Business Innovation Research/Small Business Tech Transfer (SBIR/STTR)
Lead organizationJet Propulsion Laboratory, Pasadena, CA
Start date2007-01-19
End date2007-07-23

Project contacts

Listed on TechPort itself — the most direct way to ask about this specific project.

How to get involved

This is a mature technology (TRL 7+) — the realistic path in is usually NASA's Technology Transfer Program: licensing an existing NASA patent, or a Space Act Agreement to use NASA facilities/expertise directly. NASA also runs a startup licensing program with no upfront fee for companies formed to commercialize a specific NASA technology.

None of these are guaranteed paths for this specific project — TechPort itself doesn't have an "apply" button. Reaching out to the contact(s) above with a specific question is usually the fastest way to find out what's actually open.