Abstract
Automated detection of vulnerabilities and weaknesses in binary code is a critical need at the frontier of cybersecurity research. Cybersecurity static-analysis tools aim to detect and enumerate vulnerabilities and weaknesses. Two popular tools are CVE Binary Tool (cve-bin-tool) and cwe-checker. Cve-bin-tool reports vulnerabilities using Common Vulnerabilities and Exposures (CVE) whereas cwe-checker reports weaknesses using Common Weakness Enumeration (CWE). Despite widespread use, the consistency with which these tools report vulnerabilities and weaknesses (herein, 'findings') was unaddressed. We conducted a systematic investigation of 660 unique binaries taken from a Kali Linux distribution, evaluated each binary with multiple versions of the static-analysis tools, and investigated how the findings changed according to the version of the static-analysis tool used. We expected some variation in findings commensurate with the software-development life cycle. However, the number and magnitude of the changes in findings reported across versions were substantial. New versions gave new answers.
Cite
CITATION STYLE
Reinhold, A. M., Weber, T., Lemak, C., Reimanis, D., & Izurieta, C. (2023). New Version, New Answer: Investigating Cybersecurity Static-Analysis Tool Findings. In Proceedings of the 2023 IEEE International Conference on Cyber Security and Resilience, CSR 2023 (pp. 28–35). Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1109/CSR57506.2023.10224930
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.