Automatic repair of OWASP Top 10 security vulnerabilities: A survey

19Citations
Citations of this article
54Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Current work on automatic program repair has not focused on actually prevalent vulnerabilities in web applications, such as described in the OWASP Top 10 categories, leading to a scarcely explored field, which in turn leads to a gap between industry needs and research efforts. In order to assess the extent of this gap, we have surveyed and analyzed the literature on fully automatic source-code manipulating program repair of OWASP Top 10 vulnerabilities, as well as their corresponding test suites. We find that there is a significant gap in the coverage of the OWASP Top 10 vulnerabilities, and that the test suites used to test the analyzed approaches are highly inadequate. Few approaches cover multiple OWASP Top 10 vulnerabilities, and there is no combination of existing test suites that achieves a total coverage of OWASP Top 10.

Cite

CITATION STYLE

APA

Marchand-Melsom, A., & Nguyen Mai, D. B. (2020). Automatic repair of OWASP Top 10 security vulnerabilities: A survey. In Proceedings - 2020 IEEE/ACM 42nd International Conference on Software Engineering Workshops, ICSEW 2020 (pp. 23–30). Association for Computing Machinery, Inc. https://doi.org/10.1145/3387940.3392200

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free