Sonnekalb, Tim und Knaust, Christopher-Tobias und Gruner, Bernd und Brust, Clemens-Alexander und Heinze, Thomas S. und Kurnatowski, Lynn und Schreiber, Andreas und Mäder, Patrick (2023) A Static Analysis Platform for Investigating Security Trends in Repositories. In: 1st IEEE/ACM International Workshop on Software Vulnerability, SVM 2023, Seiten 1-5. 2023 IEEE/ACM 1st International Workshop on Software Vulnerability (SVM), 2023-05-20, Melbourne, Australia. doi: 10.1109/SVM59160.2023.00005. ISBN 979-835030190-8.
PDF
331kB |
Offizielle URL: https://ieeexplore.ieee.org/document/10190574
Kurzfassung
Static analysis tools come in many forms and configurations, allowing them to handle various tasks in a (secure) development process: code style linting, bug/vulnerability detection, verification, etc., and adapt to the specific requirements of a software project, thus reducing the number of false positives.The wide range of configuration options poses a hurdle in their use for software developers, as the tools cannot be deployed out-of-the-box. However, static analysis tools only develop their full benefit if they are integrated into the software development workflow and used on regular. Vulnerability management should be integrated via version history to identify hotspots, for example.We present an analysis platform that integrates several static analysis tools that enable Git-based repositories to continuously monitor warnings across their version history. The framework is easily extensible with other tools and programming languages. We provide a visualization component in the form of a dashboard to display security trends and hotspots. Our tool can also be used to create a database of security alerts at a scale well-suited for machine learning applications such as bug or vulnerability detection.
elib-URL des Eintrags: | https://elib.dlr.de/196449/ | ||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Dokumentart: | Konferenzbeitrag (Vortrag) | ||||||||||||||||||||||||||||||||||||
Titel: | A Static Analysis Platform for Investigating Security Trends in Repositories | ||||||||||||||||||||||||||||||||||||
Autoren: |
| ||||||||||||||||||||||||||||||||||||
Datum: | 27 Juli 2023 | ||||||||||||||||||||||||||||||||||||
Erschienen in: | 1st IEEE/ACM International Workshop on Software Vulnerability, SVM 2023 | ||||||||||||||||||||||||||||||||||||
Referierte Publikation: | Ja | ||||||||||||||||||||||||||||||||||||
Open Access: | Ja | ||||||||||||||||||||||||||||||||||||
Gold Open Access: | Nein | ||||||||||||||||||||||||||||||||||||
In SCOPUS: | Ja | ||||||||||||||||||||||||||||||||||||
In ISI Web of Science: | Ja | ||||||||||||||||||||||||||||||||||||
DOI: | 10.1109/SVM59160.2023.00005 | ||||||||||||||||||||||||||||||||||||
Seitenbereich: | Seiten 1-5 | ||||||||||||||||||||||||||||||||||||
ISBN: | 979-835030190-8 | ||||||||||||||||||||||||||||||||||||
Status: | veröffentlicht | ||||||||||||||||||||||||||||||||||||
Stichwörter: | static analysis, program analysis, security dashboard, software monitoring, vulnerability management | ||||||||||||||||||||||||||||||||||||
Veranstaltungstitel: | 2023 IEEE/ACM 1st International Workshop on Software Vulnerability (SVM) | ||||||||||||||||||||||||||||||||||||
Veranstaltungsort: | Melbourne, Australia | ||||||||||||||||||||||||||||||||||||
Veranstaltungsart: | internationale Konferenz | ||||||||||||||||||||||||||||||||||||
Veranstaltungsdatum: | 20 Mai 2023 | ||||||||||||||||||||||||||||||||||||
HGF - Forschungsbereich: | Luftfahrt, Raumfahrt und Verkehr | ||||||||||||||||||||||||||||||||||||
HGF - Programm: | Raumfahrt | ||||||||||||||||||||||||||||||||||||
HGF - Programmthema: | Technik für Raumfahrtsysteme | ||||||||||||||||||||||||||||||||||||
DLR - Schwerpunkt: | Raumfahrt | ||||||||||||||||||||||||||||||||||||
DLR - Forschungsgebiet: | R SY - Technik für Raumfahrtsysteme | ||||||||||||||||||||||||||||||||||||
DLR - Teilgebiet (Projekt, Vorhaben): | R - Digitale Transformation in der Raumfahrt [SY], R - Intelligente Analysen und Methoden zur sicheren Softwareentwicklung | ||||||||||||||||||||||||||||||||||||
Standort: | Jena | ||||||||||||||||||||||||||||||||||||
Institute & Einrichtungen: | Institut für Datenwissenschaften > Datengewinnung und -mobilisierung Institut für Softwaretechnologie > Intelligente und verteilte Systeme | ||||||||||||||||||||||||||||||||||||
Hinterlegt von: | Sonnekalb, Tim | ||||||||||||||||||||||||||||||||||||
Hinterlegt am: | 07 Aug 2023 10:03 | ||||||||||||||||||||||||||||||||||||
Letzte Änderung: | 17 Okt 2024 08:18 |
Nur für Mitarbeiter des Archivs: Kontrollseite des Eintrags