vix.ing · top · new · best · stats · spec

On the combination of static analysis for software security assessment\n -- a case study of an open-source e-government project

2021/03/14 by Anh Nguyen‐Duc, Manh Viet Do, Nguyen-Duc, Anh +5 · 1 citation
Computer Science · #Information and Cyber Security #Software Engineering Research #Software Reliability and Analysis Research

paper · pdf · doi:10.48550/arxiv.2103.08010

Abstract

Static Application Security Testing (SAST) is a popular quality assurance\ntechnique in software engineering. However, integrating SAST tools into\nindustry-level product development and security assessment poses various\ntechnical and managerial challenges. In this work, we reported a longitudinal\ncase study of adopting SAST as a part of a human-driven security assessment for\nan open-source e-government project. We described how SASTs are selected,\nevaluated, and combined into a novel approach for software security assessment.\nThe approach was preliminarily evaluated using semi-structured interviews. Our\nresult shows that (1) while some SAST tools out-perform others, it is possible\nto achieve better performance by combining more than one SAST tools and (2)\nSAST tools should be used towards a practical performance and in the\ncombination with triangulated approaches for human-driven vulnerability\nassessment in real-world projects.\n

Cited by

Related