New Version, New Answer: Investigating Cybersecurity Static-Analysis Tool Findings

13Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Automated detection of vulnerabilities and weaknesses in binary code is a critical need at the frontier of cybersecurity research. Cybersecurity static-analysis tools aim to detect and enumerate vulnerabilities and weaknesses. Two popular tools are CVE Binary Tool (cve-bin-tool) and cwe-checker. Cve-bin-tool reports vulnerabilities using Common Vulnerabilities and Exposures (CVE) whereas cwe-checker reports weaknesses using Common Weakness Enumeration (CWE). Despite widespread use, the consistency with which these tools report vulnerabilities and weaknesses (herein, 'findings') was unaddressed. We conducted a systematic investigation of 660 unique binaries taken from a Kali Linux distribution, evaluated each binary with multiple versions of the static-analysis tools, and investigated how the findings changed according to the version of the static-analysis tool used. We expected some variation in findings commensurate with the software-development life cycle. However, the number and magnitude of the changes in findings reported across versions were substantial. New versions gave new answers.

Cite

CITATION STYLE

APA

Reinhold, A. M., Weber, T., Lemak, C., Reimanis, D., & Izurieta, C. (2023). New Version, New Answer: Investigating Cybersecurity Static-Analysis Tool Findings. In Proceedings of the 2023 IEEE International Conference on Cyber Security and Resilience, CSR 2023 (pp. 28–35). Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1109/CSR57506.2023.10224930

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free