Static Analysis and Penetration Testing from the Perspective of Maintenance Teams

被引:8
作者
Ceccato, Mariano [1 ]
Scandariato, Riccardo [2 ]
机构
[1] Fdn Bruno Kessler, Trento, Italy
[2] Chalmers & Univ Gothenburg, Gothenburg, Sweden
来源
ESEM'16: PROCEEDINGS OF THE 10TH ACM/IEEE INTERNATIONAL SYMPOSIUM ON EMPIRICAL SOFTWARE ENGINEERING AND MEASUREMENT | 2016年
关键词
Software maintenance; Static analysis; Penetration testing;
D O I
10.1145/2961111.2962611
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Static analysis and penetration testing are common techniques used to discover security bugs in implementation code. Penetration testing is often performed in black-box way by probing the attack surface of a running system and discovering its security holes. Static analysis techniques operate in a white-box way by analyzing the source code of a system and identifying security weaknesses. Because of their different nature, the two techniques report their findings in two different ways. This paper presents an exploratory study meant to determine whether a vulnerability report generated by a security tool based on static analysis is more or less useful than a report generated by a security tool based on penetration testing. The usefulness is judged from the perspective of the developers that have to devise a vulnerability-fixing patch. The initial results show an advantage when using penetration testing in one of the two cases we investigated.
引用
收藏
页数:6
相关论文
共 14 条
[1]  
Antunes N., 2009, IEEE PAC RIM INT S D
[2]  
Austin A., INT S EMP SOFTW ENG
[3]  
Ceccato M., 2016, REPLICATION PACKAGE
[4]   A family of experiments to assess the effectiveness and efficiency of source code obfuscation techniques [J].
Ceccato, Mariano ;
Di Penta, Massimiliano ;
Falcarin, Paolo ;
Ricca, Filippo ;
Torchiano, Marco ;
Tonella, Paolo .
EMPIRICAL SOFTWARE ENGINEERING, 2014, 19 (04) :1040-1074
[5]  
Cohen J., 2013, Statistical power analysis for the behavioral sciences, DOI DOI 10.4324/9780203771587
[6]  
Devore J.L., 2007, Probability and Statistics for Engineering and the Sciences, V7th
[7]  
Grissom RJ., 2005, EFFECT SIZES RES BRO
[8]  
Motulsky H.J., 2010, INTUITIVE BIOSTATIST, V2nd
[9]  
R Core Team, 2015, R: a language and environment for statistical computing
[10]  
Scandariato R, 2013, PROC INT SYMP SOFTW, P451, DOI 10.1109/ISSRE.2013.6698898