AppSecNews
SAST Commercial Established

Klocwork

by Perforce Software

Whole program static analysis for C, C++, C# and Java with compliance reporting against MISRA, CERT and AUTOSAR coding standards.

Visit perforce.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Klocwork in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Language list: JavaScript, Python and Kotlin support has been added at various points, confirm current coverage
  • Integration list: verify against the current connector catalog

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Klocwork runs static analysis over source code by building a whole program model as the code compiles, then running checkers against that model. The distinguishing piece is interprocedural dataflow. Rather than matching patterns line by line, it tracks values across function boundaries and across translation units to reach conclusions about null dereferences, buffer overruns, uninitialized memory, resource leaks and tainted input arriving at a sensitive sink. That whole program view is what makes it usable on large C and C++ code where the defect and its root cause sit in different files.

Alongside defect detection it carries compliance checker packs mapped to the standards regulated industries are audited against: MISRA for automotive C and C++, CERT secure coding, CWE and AUTOSAR. Reports are produced per standard with traceability back to the offending line, which is the artifact an assessor asks for. Klocwork also supports incremental analysis on a developer machine, so a build of changed files can be checked against a previously computed system model without re-analyzing the whole tree.

Where it fits

Two places. On the developer desktop through IDE plugins and a command line connector, where incremental mode gives feedback on changed files before a push. And in the build pipeline, where a full system analysis runs against the integration branch and results land on a central server for triage, historical comparison and compliance reporting. It requires a working build: the analysis attaches to your compiler invocations, so a project that cannot be built cleanly cannot be fully analyzed. Ownership usually sits with a software quality or functional safety group rather than a security team.

Strengths

  • Interprocedural, whole program dataflow that follows values across files, which is where serious memory safety defects in C and C++ actually live.
  • Compliance reporting against MISRA, CERT, CWE and AUTOSAR with the documentation trail certification work requires.
  • Deep C and C++ handling, including older dialects and embedded cross compilers that newer scanners do not parse.

Limitations

  • Build integration is the price of the analysis depth. Unusual build systems and cross compilers take real onboarding effort.
  • A full system analysis on a large codebase is slow and resource hungry, which pushes it toward nightly runs rather than per pull request.
  • Tuning is mandatory. Default checker sets produce more findings than most teams can absorb in the first months.

Who it suits

A good fit for embedded, automotive, medical device and aerospace teams who need defensible compliance evidence alongside defect detection and who already build with a supported toolchain. Less appropriate for a web application team on a polyglot stack, where a lighter scanner with per pull request feedback will fit with far less overhead.

Used Klocwork? Recommend it under your own name and title.

Recommend this tool