Mitigating false positive static analysis warnings: Progress, challenges, and opportunities

Z Guo, T Tan, S Liu, X Liu, W Lai, Y Yang… - IEEE Transactions …, 2023 - ieeexplore.ieee.org
Static analysis (SA) tools can generate useful static warnings to reveal the problematic code
snippets in a software system without dynamically executing the corresponding source code …

{WHIP}: Improving Static Vulnerability Detection in Web Application by Forcing tools to Collaborate

F Al-Kassar, L Compagna, D Balzarotti - 32nd USENIX Security …, 2023 - usenix.org
Improving the accuracy of static application security testing (SAST) is key to fight critical
vulnerabilities and increase the security of the Web. However, even state-of-the-art …

Testability Tarpits-Navigating the Challenges of Static Tools in Web Applications

F Al-Kassar - 2023 - theses.hal.science
The goal of this thesis was to evaluate the effectiveness of a combination of commercial and
open source security scanners. Through experimentation, we identified various code …

[图书][B] Finding Attacks and Vulnerabilities in Critical Systems

D Das - 2023 - search.proquest.com
Starting from that historic moment in 1948 when the first ever piece of software was written
and successfully executed on a stored-program computer to this era of supercomputers …