On the detection and analysis of software security vulnerabilities

Chaman Wijesiriwardana, Prasad Wimalaratne · 2017

Software security is considered as an important issue in the modern software development practices. According to the literature, the benefits of the existing static analysis tools in isolation for security specific analysis of multiple large-scale software systems is highly questionable. In particular, the existing static analysis tools are not facilitating different analysis directions such as classification of vulnerabilities and analysis of multiple projects for multiple versions. To tackle this problem, this paper presents a conceptual framework and a proof-of-concept implementation to integrate the outputs of multiple static analysis tools into one place to perform a wide range of software security analyses. The rich features of the framework have been demonstrated by using two different application scenarios. We used a case study to evaluate the usefulness and the extensibility of our framework in performing in-depth security analysis.

Read the paper · More papers on PaperTik