Glossary · Automation software engineering and architecture
Dynamic code analysis
Also known as: Dynamic analysis, Runtime analysis
German: Dynamische Codeanalyse
In software engineering, dynamic code analysis is the examination of software by executing it and observing its behavior, for example measuring coverage, detecting memory errors, race conditions or performance problems, or fuzzing interfaces with unexpected inputs.
- Software engineering
In one sentence
Dynamic code analysis examines software while it runs, detecting memory errors, races, coverage gaps or performance problems.
Example
Running the communication stack's test suite under a memory sanitizer reveals a read past the end of a receive buffer that no functional test had noticed.
How it applies
- Engineering: Common techniques are coverage measurement, memory and thread sanitizers, profiling, runtime assertion checking and fuzz testing. They find defects that only appear during execution.
- Security: Fuzzing of network-facing interfaces is an effective way to find robustness and security defects in industrial devices. Secure development processes under IEC 62443-4-1 include such testing.
- Documentation: Record which dynamic analyses were run, on which version, with which tools and results. These reports are part of verification evidence and are often requested in security assessments.
Dynamic vs. static code analysis
Static code analysis examines source or binary code without running it and can check all paths in principle, but may report false positives. Dynamic analysis only sees the paths actually executed, but its findings are real behavior. The two complement each other.
Fault injection is a related technique that deliberately introduces faults to test error handling.