Browse wiki

From Navigators

Jump to: navigation, search
Publication:IEEETR 2018
Abstract Static analysis tools are recurrently used Static analysis tools are recurrently used by developers to search for vulnerabilities in the source code of web applications. However, distinct tools provide different results depending on factors such as the complexity of the code under analysis and the application scenario, thus missing some of the vulnerabilities while reporting false problems. Benchmarks can be used to assess and compare different systems or components, however, existing benchmarks have strong representativeness limitations, disregarding the specificities of the environment where the tools under benchmarking will be used. In this paper, we propose a benchmark for assessing and comparing static analysis tools in terms of their capability to detect security vulnerabilities. The benchmark considers four real-world development scenarios, including workloads composed by real web applications with different goals and constraints, ranging from low budget to highend applications. Our benchmark was implemented and assessed experimentally using a set of 134 WordPress plugins, which served as basis for the evaluation of five free PHP static analysis tools. Results clearly show that the best solution depends on the deployment scenario and class of vulnerability being detected, therefore highlighting the importance of these aspects in the design of the benchmark and of future static analysis tools. hmark and of future static analysis tools.
Author Paulo Nunes + , Ibéria Medeiros + , José Fonseca + , Nuno Ferreira Neves + , Miguel Correia + , Marco Vieira +
Journal IEEE Transactions on Reliability  +
Key IEEETR 2018  +
Month sep  +
NumPubDate 2,018.09  +
Pages 1159 – 1175  +
ResearchLine Fault and Intrusion Tolerance in Open Distributed Systems (FIT) +
Title Benchmarking Static Analysis Tools for Web Security  +
Type article  +
Volume 67  +
Year 2018  +
Has improper value forThis property is a special property in this wiki. Url  +
Categories Publication  +
Modification dateThis property is a special property in this wiki. 10 February 2019 02:38:52  +
NumberThis property is a special property in this wiki. 3  +
hide properties that link here 
  No properties link to this page.
 

 

Enter the name of the page to start browsing from.
Views
Personal tools
Toolbox
Navigators toolbox