Detecting security vulnerabilities with static analysis-A case study

14Citations
Citations of this article
33Readers
Mendeley users who have this article in their library.

Abstract

Many security vulnerabilities can be detected by static analysis. This paper is a case study and a performance comparison of four open-source static analysis tools and plugins (PMD, SpotBugs, Find Security Bugs, and SonarQube) on Java source code. Experiments have been conducted on the widely used Juliet Test Suite with respect to six selected weaknesses from the official Top 25 list of Common Weakness Enumeration. In this study, analysis metrics have been calculated for helping Java developers decide which tools can be used when checking their programs for security vulnerabilities. It turned out that particular weaknesses are best detected with particular tools.

Cite

CITATION STYLE

APA

Alqaradaghi, M., Morseorcid, G., & Kozsik, T. (2022). Detecting security vulnerabilities with static analysis-A case study. Pollack Periodica, 17(2), 1–7. https://doi.org/10.1556/606.2021.00454

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free