2020
DOI: 10.32604/cmc.2020.010885
|View full text |Cite
|
Sign up to set email alerts
|

Benchmarking Approach to Compare Web Applications Static Analysis Tools Detecting OWASP Top Ten Security Vulnerabilities

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
5
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
5
2
1

Relationship

1
7

Authors

Journals

citations
Cited by 11 publications
(5 citation statements)
references
References 23 publications
0
5
0
Order By: Relevance
“…However, their bench-marking approach requires manual code review, which does not scale. Other studies, such as [20], focus on SAST tools for detecting vulnerabilities and find that the true positive and false positive rates vary widely across tools and across different types of vulnerabilities. Croft et al [21] compares open-source, rule-based SAST tools with learning-based software vulnerability prediction models for C/C++ software systems.…”
Section: Comparing Static Application Security Testing (Sast) and Dyn...mentioning
confidence: 99%
“…However, their bench-marking approach requires manual code review, which does not scale. Other studies, such as [20], focus on SAST tools for detecting vulnerabilities and find that the true positive and false positive rates vary widely across tools and across different types of vulnerabilities. Croft et al [21] compares open-source, rule-based SAST tools with learning-based software vulnerability prediction models for C/C++ software systems.…”
Section: Comparing Static Application Security Testing (Sast) and Dyn...mentioning
confidence: 99%
“…Finally, a paper [8] can be examined that presents a benchmarking approach [55] to study the performance of seven static tools (five commercial tools) with a new methodology proposal. The benchmark is representative and it is designed for the vulnerability categories included in the known standard OWASP Top Ten project for SAST tools evaluations.…”
Section: Sast Tools Comparisons Studiesmentioning
confidence: 99%
“…An adequate test bench must be credible, portable, representative, require minimum changes and be easy to implement, and the tools execution must be under the same conditions [10]. We have investigated several security benchmarks for web applications as Wavsep used in the comparisons of [66,67]; Securebench Micro Project used in the works of [68,69]; Software Assurance Metrics And Tool Evaluation (SAMATE) project of National Institute of Standards and Technology (NIST) used in several works [9,28,[70][71][72][73]; OWASP benchmark project [14]; Delta-bench by Pashchenko et al [74] and OWASP Top Ten Benchmark [55] adapted for OWASP Top Ten 2013 and 2017 vulnerability categories projects and designed for static analysis only used in the work of Bermejo et al [8].…”
Section: Benchmark Selectionmentioning
confidence: 99%
See 1 more Smart Citation
“…For more information about benchmarking static analysis tools, please see page 1558 from the book [16].…”
mentioning
confidence: 99%