Evaluation of Static Analysis Tools for Finding Vulnerabilities in Java and C/C++ Source Code

05/23/2018
by   Rahma Mahmood, et al.
0

It is quite common for security testing to be delayed until after the software has been developed, but vulnerabilities may get noticed throughout the implementation phase and the earlier they are discovered, the easier and cheaper it will be to fix them. Software development processes such as the secure software development lifecycle incorporates security at every stage of the design and development process. Static code scanning tools find vulnerabilities in code by highlighting potential security flaws and offer examples on how to resolve them, and some may even modify the code to remove the susceptibility. This paper compares static analysis tools for Java and C/C++ source code, and explores their pros and cons.

READ FULL TEXT

page 2

page 4

page 5

page 6

research
05/23/2018

Evaluation of Static Analysis Tools for Finding Vulunerbailities in Java and C/C++ Source Code

It is quite common for security testing to be delayed until after the so...
research
02/01/2023

Developing Hands-on Labs for Source Code Vulnerability Detection with AI

As the role of information and communication technologies gradually incr...
research
04/07/2020

Vulnerabilities Mapping based on OWASP-SANS: a Survey for Static Application Security Testing (SAST)

The delivery of a framework in place for secure application development ...
research
07/07/2022

Towards Immediate Feedback for Security Relevant Code in Development Environments

Nowadays, the correct use of cryptography libraries is essential to ensu...
research
05/07/2021

Conversational Code Analysis: The Future of Secure Coding

The area of software development and secure coding can benefit significa...
research
06/29/2019

Análise Estática de Código-Fonte

This article presents a theoretical summary of the source code static an...
research
07/04/2019

CARVE: Practical Security-Focused Software Debloating Using Simple Feature Set Mappings

Software debloating is an emerging field of study aimed at improving the...

Please sign up or login with your details

Forgot password? Click here to reset