Gentsch, Christoph und Krishnamurthy, Rohan und Heinze, Thomas (2021) Benchmarking Open-Source Static Analyzers for Security Testing for C. In: 9th International Symposium on Leveraging Applications of Formal Methods, Verification and Validation, ISoLA 2020, 12479, Seiten 182-198. Springer. 9th International Symposium On Leveraging Applications of Formal Methods, Verification and Validation, 2021-10-17 - 2021-10-29, Rhodes, Greece. doi: 10.1007/978-3-030-83723-5_13. ISBN 978-303083722-8. ISSN 0302-9743.
PDF
- Nur DLR-intern zugänglich
482kB |
Offizielle URL: https://link.springer.com/chapter/10.1007%2F978-3-030-83723-5_13
Kurzfassung
As the number of available static analysis security testing (SAST) tools grows, the more difficult it becomes for developers to decide which tool(s) to use. We report on our evaluation of 11 open-source general-purpose SAST tools for the C programming language on the SARD Juliet Test Suite and of six tools on the Wireshark software. In line with the previous work, we find that there is no single superior tool, though sound tools performed the best on the Juliet test cases.
elib-URL des Eintrags: | https://elib.dlr.de/143645/ | ||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Dokumentart: | Konferenzbeitrag (Vortrag) | ||||||||||||||||
Titel: | Benchmarking Open-Source Static Analyzers for Security Testing for C | ||||||||||||||||
Autoren: |
| ||||||||||||||||
Datum: | 2021 | ||||||||||||||||
Erschienen in: | 9th International Symposium on Leveraging Applications of Formal Methods, Verification and Validation, ISoLA 2020 | ||||||||||||||||
Referierte Publikation: | Ja | ||||||||||||||||
Open Access: | Nein | ||||||||||||||||
Gold Open Access: | Nein | ||||||||||||||||
In SCOPUS: | Ja | ||||||||||||||||
In ISI Web of Science: | Nein | ||||||||||||||||
Band: | 12479 | ||||||||||||||||
DOI: | 10.1007/978-3-030-83723-5_13 | ||||||||||||||||
Seitenbereich: | Seiten 182-198 | ||||||||||||||||
Herausgeber: |
| ||||||||||||||||
Verlag: | Springer | ||||||||||||||||
Name der Reihe: | Lecture Notes in Computer Science | ||||||||||||||||
ISSN: | 0302-9743 | ||||||||||||||||
ISBN: | 978-303083722-8 | ||||||||||||||||
Status: | veröffentlicht | ||||||||||||||||
Stichwörter: | static analysis, SAST, C, security analysis, benchmark | ||||||||||||||||
Veranstaltungstitel: | 9th International Symposium On Leveraging Applications of Formal Methods, Verification and Validation | ||||||||||||||||
Veranstaltungsort: | Rhodes, Greece | ||||||||||||||||
Veranstaltungsart: | internationale Konferenz | ||||||||||||||||
Veranstaltungsbeginn: | 17 Oktober 2021 | ||||||||||||||||
Veranstaltungsende: | 29 Oktober 2021 | ||||||||||||||||
HGF - Forschungsbereich: | Luftfahrt, Raumfahrt und Verkehr | ||||||||||||||||
HGF - Programm: | Raumfahrt | ||||||||||||||||
HGF - Programmthema: | Technik für Raumfahrtsysteme | ||||||||||||||||
DLR - Schwerpunkt: | Raumfahrt | ||||||||||||||||
DLR - Forschungsgebiet: | R SY - Technik für Raumfahrtsysteme | ||||||||||||||||
DLR - Teilgebiet (Projekt, Vorhaben): | R - Intelligente Analysen und Methoden zur sicheren Softwareentwicklung | ||||||||||||||||
Standort: | Jena | ||||||||||||||||
Institute & Einrichtungen: | Institut für Datenwissenschaften > Sichere Digitale Systeme | ||||||||||||||||
Hinterlegt von: | Heinze, Thomas | ||||||||||||||||
Hinterlegt am: | 01 Sep 2021 15:49 | ||||||||||||||||
Letzte Änderung: | 24 Apr 2024 20:43 |
Nur für Mitarbeiter des Archivs: Kontrollseite des Eintrags