首页> 外文期刊>Fortschritte der Physik >Benchmarking Static Analysis Tools for Web Security
【24h】

Benchmarking Static Analysis Tools for Web Security

机译:用于Web安全性的基准静态分析工具

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Static analysis tools are recurrently used by developers to search for vulnerabilities in the source code of web applications. However, distinct tools provide different results depending on factors such as the complexity of the code under analysis and the application scenario; thus, missing some of the vulnerabilities while reporting false problems. Benchmarks can be used to assess and compare different systems or components, however, existing benchmarks have strong representativeness limitations, disregarding the specificities of the environment, where the tools under benchmarking will be used. In this paper, we propose a benchmark for assessing and comparing static analysis tools in terms of their capability to detect security vulnerabilities. The benchmark considers four real-world development scenarios, including workloads composed of real web applications with different goals and constraints, ranging from low budget to high-end applications. Our benchmark was implemented and assessed experimentally using a set of 134 Word Press plugins, which served as the basis for the evaluation of five free PHP static analysis tools. Results clearly show that the best solution depends on the deployment scenario and class of vulnerability being detected; therefore, highlighting the importance of these aspects in the design of the benchmark and of future static analysis tools.
机译:开发人员常常使用静态分析工具来搜索Web应用程序源代码中的漏洞。然而,不同的工具提供了不同的结果,具体取决于诸如在分析和应用方案下的代码的复杂性等因素;因此,缺少一些漏洞,同时报告错误问题。基准可用于评估和比较不同的系统或组件,然而,现有的基准具有很强的代表性限制,忽视环境的特殊性,将使用基准下的工具。在本文中,我们提出了一种用于评估和比较静态分析工具的基准,以检测安全漏洞的能力。该基准测试考虑了四种现实的发展方案,包括由具有不同目标和约束的真实Web应用程序组成的工作负载,从低预算到高端应用程序。我们的基准测试并通过一组134个单词按插件实施并评估,该插件作为评估五个免费PHP静态分析工具的基础。结果清楚地表明,最佳解决方案取决于检测到的部署方案和漏洞类;因此,突出了这些方面在基准测试和未来静态分析工具设计中的重要性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号