Visible to the public Techniques and Tools for Advanced Software Vulnerability Detection

TitleTechniques and Tools for Advanced Software Vulnerability Detection
Publication TypeConference Paper
Year of Publication2020
AuthorsPereira, José D’Abruzzo
Conference Name2020 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)
Date PublishedOct. 2020
PublisherIEEE
ISBN Number978-1-7281-7735-9
KeywordsBenchmark testing, Manuals, Measurement, Metrics, metrics testing, Open Source Software, pubcrawl, security, software metrics, software vulnerability detection, static code analysis, Task Analysis, text mining, Tools
AbstractSoftware is frequently deployed with vulnerabilities that may allow hackers to gain access to the system or information, leading to money or reputation losses. Although there are many techniques to detect software vulnerabilities, their effectiveness is far from acceptable, especially in large software projects, as shown by several research works. This Ph.D. aims to study the combination of different techniques to improve the effectiveness of vulnerability detection (increasing the detection rate and decreasing the number of false-positives). Static Code Analysis (SCA) has a good detection rate and is the central technique of this work. However, as SCA reports many false-positives, we will study the combination of various SCA tools and the integration with other detection approaches (e.g., software metrics) to improve vulnerability detection capabilities. We will also study the use of such combination to prioritize the reported vulnerabilities and thus guide the development efforts and fixes in resource-constrained projects.
URLhttps://ieeexplore.ieee.org/document/9307657
DOI10.1109/ISSREW51248.2020.00049
Citation Keypereira_techniques_2020