DocumentCode :
1768128
Title :
Evaluation of static analysis tools for software security
Author :
AlBreiki, Hamda Hasan ; Mahmoud, Qusay H.
Author_Institution :
Dept. of Comput. Inf. Sci., Higher Colleges of Technol., United Arab Emirates
fYear :
2014
fDate :
9-11 Nov. 2014
Firstpage :
93
Lastpage :
98
Abstract :
Security has been always treated as an add-on feature in the software development lifecycle, and addressed by security professionals using firewalls, proxies, intrusion prevention systems, antivirus and platform security. Software is at the root of all common computer security problems, and hence hackers don´t create security holes, but rather exploit them. Security holes in software applications are the result of bad design and implementation of software systems and applications. To address this problem, several initiatives for integrating security in the software development lifecycle have been proposed, along with tools to support a security-centric software development lifecycle. This paper introduces a framework for evaluating security static analysis tools such as source code analyzers, and offers evaluation of non-commercial static analysis tools such as Yasca, CAT.NET, and FindBugs. In order to evaluate the effectiveness of such tools, common software weaknesses are defined based on CWE/SANS Top 25, OWASP Top Ten and NIST source code weaknesses. The evaluation methodology is based on the NIST Software Assurance Metrics And Tool Evaluation (SAMATE). Results show that security static analysis tools are, to some extent, effective in detecting security holes in source code; source code analyzers are able to detect more weaknesses than bytecode and binary code scanners; and while tools can assist the development team in security code review activities, they are not enough to uncover all common weaknesses in software. The new test cases developed for this research have been contributed to the NIST Software Assurance Reference Dataset (samate.nist.gov/SARD).
Keywords :
program diagnostics; security of data; software metrics; software tools; source code (software); CAT.NET; CWE-SANS Top 25; FindBugs; NIST SAMATE; NIST software assurance metrics and tool evaluation; NIST software assurance reference dataset; NIST source code weaknesses; OWASP Top Ten; Yasca; antivirus; firewalls; hackers; intrusion prevention systems; noncommercial static analysis tools; platform security; proxies; security holes; security static analysis tools; security-centric software development lifecycle; software security; source code analyzers; Binary codes; Computer architecture; Industries; Java; NIST; Security; Software; OWASP; SAMATE; security metrics; software security; static analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Innovations in Information Technology (INNOVATIONS), 2014 10th International Conference on
Conference_Location :
Al Ain
Print_ISBN :
978-1-4799-7210-4
Type :
conf
DOI :
10.1109/INNOVATIONS.2014.6987569
Filename :
6987569
Link To Document :
بازگشت