Myths and Facts About Static Application Security Testing Tools: An Action Research at Telenor Digital

被引:23
|
作者
Oyetoyan, Tosin Daniel [1 ]
Milosheska, Bisera [2 ]
Grini, Mari [2 ]
Cruzes, Daniela Soares [1 ]
机构
[1] SINTEF Digital, Dept Software Engn Safety & Secur, Trondheim, Norway
[2] Telenor Digital, Oslo, Norway
来源
AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING, XP 2018 | 2018年 / 314卷
关键词
Security defects; Agile; Static analysis; Static application security testing; Software security;
D O I
10.1007/978-3-319-91602-6_6
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
It is claimed that integrating agile and security in practice is challenging. There is the notion that security is a heavy process, requires expertise, and consumes developers' time. These contrast with the agile vision. Regardless of these challenges, it is important for organizations to address security within their agile processes since critical assets must be protected against attacks. One way is to integrate tools that could help to identify security weaknesses during implementation and suggest methods to refactor them. We used quantitative and qualitative approaches to investigate the efficiency of the tools and what they mean to the actual users (i.e. developers) at Telenor Digital. Our findings, although not surprising, show that several barriers exist both in terms of tool's performance and developers' perceptions. We suggest practical ways for improvement.
引用
收藏
页码:86 / 103
页数:18
相关论文
共 14 条
  • [1] An Extensive Comparison of Static Application Security Testing Tools
    Esposito, Matteo
    Falaschi, Valentina
    Falessi, Davide
    PROCEEDINGS OF 2024 28TH INTERNATION CONFERENCE ON EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING, EASE 2024, 2024, : 69 - 78
  • [2] Data-Driven Improvement of Static Application Security Testing Service: An Experience Report in Visma
    Iovan, Monica
    Cruzes, Daniela Soares
    PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT, PROFES 2022, 2022, 13709 : 157 - 170
  • [3] Constructing Benchmarks for Supporting Explainable Evaluations of Static Application Security Testing Tools
    Hao, Gaojian
    Li, Feng
    Huo, Wei
    Sun, Qing
    Wang, Wei
    Li, Xinhua
    Zou, Wei
    2019 13TH INTERNATIONAL SYMPOSIUM ON THEORETICAL ASPECTS OF SOFTWARE ENGINEERING (TASE 2019), 2019, : 65 - 72
  • [4] Comparison and Evaluation on Static Application Security Testing (SAST) Tools for Java']Java
    Li, Kaixuan
    Chen, Sen
    Fan, Lingling
    Feng, Ruitao
    Liu, Han
    Liu, Chengwei
    Liu, Yang
    Chen, Yixiang
    PROCEEDINGS OF THE 31ST ACM JOINT MEETING EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, ESEC/FSE 2023, 2023, : 921 - 933
  • [5] FOSS Version Differentiation as a Benchmark for Static Analysis Security Testing Tools
    Pashchenko, Ivan
    ESEC/FSE 2017: PROCEEDINGS OF THE 2017 11TH JOINT MEETING ON FOUNDATIONS OF SOFTWARE ENGINEERING, 2017, : 1056 - 1058
  • [6] Delta-Bench: Differential Benchmark for Static Analysis Security Testing Tools
    Pashchenko, Ivan
    Dashevskyi, Stanislav
    Massacci, Fabio
    11TH ACM/IEEE INTERNATIONAL SYMPOSIUM ON EMPIRICAL SOFTWARE ENGINEERING AND MEASUREMENT (ESEM 2017), 2017, : 163 - 168
  • [7] Using ChatGPT as a Static Application Security Testing Tool
    Bakhshandeh, Atieh
    Keramatfar, Abdalsamad
    Norouzi, Amir
    Chekidehkhoun, Mohammad M.
    ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 15 (03): : 51 - 58
  • [8] Evaluating C/C plus plus Vulnerability Detectability of Query-Based Static Application Security Testing Tools
    Li, Zongjie
    Liu, Zhibo
    Wong, Wai Kin
    Ma, Pingchuan
    Wang, Shuai
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) : 4600 - 4618
  • [9] Research on Static Analysis Technology of Android Application Security Defects
    Chen, Lu
    Liu, Xing
    Ma, Yuan-yuan
    Shi, Cong-cong
    Li, Ni-ge
    2016 INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING AND AUTOMATION (ICEEA 2016), 2016,
  • [10] Input Splitting for Cloud-Based Static Application Security Testing Platforms
    Christakis, Maria
    Cottenier, Thomas
    Filieri, Antonio
    Luo, Linghui
    Mansur, Muhammad Numair
    Pike, Lee
    Rosner, Nicolas
    Schaf, Martin
    Sengupta, Aritra
    Visser, Willem
    PROCEEDINGS OF THE 30TH ACM JOINT MEETING EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, ESEC/FSE 2022, 2022, : 1367 - 1378