DocumentCode
1768128
Title
Evaluation of static analysis tools for software security
Author
AlBreiki, Hamda Hasan ; Mahmoud, Qusay H.
Author_Institution
Dept. of Comput. Inf. Sci., Higher Colleges of Technol., United Arab Emirates
fYear
2014
fDate
9-11 Nov. 2014
Firstpage
93
Lastpage
98
Abstract
Security has been always treated as an add-on feature in the software development lifecycle, and addressed by security professionals using firewalls, proxies, intrusion prevention systems, antivirus and platform security. Software is at the root of all common computer security problems, and hence hackers don´t create security holes, but rather exploit them. Security holes in software applications are the result of bad design and implementation of software systems and applications. To address this problem, several initiatives for integrating security in the software development lifecycle have been proposed, along with tools to support a security-centric software development lifecycle. This paper introduces a framework for evaluating security static analysis tools such as source code analyzers, and offers evaluation of non-commercial static analysis tools such as Yasca, CAT.NET, and FindBugs. In order to evaluate the effectiveness of such tools, common software weaknesses are defined based on CWE/SANS Top 25, OWASP Top Ten and NIST source code weaknesses. The evaluation methodology is based on the NIST Software Assurance Metrics And Tool Evaluation (SAMATE). Results show that security static analysis tools are, to some extent, effective in detecting security holes in source code; source code analyzers are able to detect more weaknesses than bytecode and binary code scanners; and while tools can assist the development team in security code review activities, they are not enough to uncover all common weaknesses in software. The new test cases developed for this research have been contributed to the NIST Software Assurance Reference Dataset (samate.nist.gov/SARD).
Keywords
program diagnostics; security of data; software metrics; software tools; source code (software); CAT.NET; CWE-SANS Top 25; FindBugs; NIST SAMATE; NIST software assurance metrics and tool evaluation; NIST software assurance reference dataset; NIST source code weaknesses; OWASP Top Ten; Yasca; antivirus; firewalls; hackers; intrusion prevention systems; noncommercial static analysis tools; platform security; proxies; security holes; security static analysis tools; security-centric software development lifecycle; software security; source code analyzers; Binary codes; Computer architecture; Industries; Java; NIST; Security; Software; OWASP; SAMATE; security metrics; software security; static analysis;
fLanguage
English
Publisher
ieee
Conference_Titel
Innovations in Information Technology (INNOVATIONS), 2014 10th International Conference on
Conference_Location
Al Ain
Print_ISBN
978-1-4799-7210-4
Type
conf
DOI
10.1109/INNOVATIONS.2014.6987569
Filename
6987569
Link To Document