On the Effects of Program Slicing for Vulnerability Detection during Code Inspection: Extended Abstract
Aurora Papotti, Fabio Massacci, Katja Tuma · 2024
[Background]: Slicing has been first introduced to support debugging as a fault localization technique. Yet, program slicing as support for identifying vulnerabilities during code inspection has received limited attention. [Aims]: Evaluate the effectiveness of slicing as a general concept to support code inspectors while detecting vulnerabilities into source code. [Method]: We designed a controlled experiment which goal is identifying the vulnerable lines in original or sliced Java files from Apache Tomcat. The designed treatments differ in the pair (Vulnerability, Original/Sliced file) with a balanced design with four vulnerabilities from the OWASP Top 10. The participants are MSc students attending security courses (n = 236). [Observations]: By using a notion of neighborhood based on the context size of the command git diff we observed that slicing helps in 'finding something' as opposed to 'finding nothing'. However, once some correct lines have been found, analyzing a slice and analyzing the original file are statistically equivalent.