Abstract
Static Application Security Testing (SAST) is a popular quality assurance technique in software engineering. However, integrating SAST tools into industry-level product development and security assessment poses various technical and managerial challenges. In this work, we reported a longitudinal case study of adopting SAST as a part of a human-driven security assessment for an open-source e-government project. We described how SASTs are selected, evaluated, and combined into a novel approach for software security assessment. The approach was preliminarily evaluated using semi-structured interviews. Our result shows that (1) while some SAST tools out-perform others, it is possible to achieve better performance by combining more than one SAST tools and (2) SAST tools should be used towards a practical performance and in the combination with triangulated approaches for human-driven vulnerability assessment in real-world projects.
Cite
CITATION STYLE
Nguyen-Duc, A., Do, M.-V., Luong-Hong, Q., Nguyen-Khac, K., & Truong-Anh, H. (2021). On the Combination of Static Analysis for Software Security Assessment – A Case Study of an Open-Source e-Government Project. Advances in Science, Technology and Engineering Systems Journal, 6(2), 921–932. https://doi.org/10.25046/aj0602105
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.