The present work aims to clarify the reliability of the Static Application Security Testing (SAST) tools both in the world of free software and in proprietary software, comparing both. Throughout the work, the state of the art in SAST techniques is analyzed, as well as a pilot experiment is carried out. In order to carry out the pilot experiment, an analysis environment has been developed that allows the different analyses to be carried out in a methodical, repeatable and effective way. A total of three tools have been studied (Fortify, SonarQube and VisualCodeGreeper) with which three programming languages (C++, Java and PHP) have been analysed in search of five specific CWE, with samples coming from SAMATE code repositories. Thro...
U ovom radu proučene su tehnike te načini na koji općenito rade alati za statičku analizu koda koji ...
Security deficiencies that occur in web applications can have major consequences. PHP is a language ...
Esta tesis presenta una revisión general del estado de las herramientas de análisis de código estáti...
Static Application Security Testing Tools (SAST) is a security tool that claims to help with securit...
Static Application Security Testing (SAST) is a popular quality assurance technique in software engi...
Security testing is a widely applied measure to evaluate and improve software security by identifyin...
Abstract—Modern web applications play a pivotal role in our digital society. Motivated by the many s...
The goal of SAST-tools is to help developers coding software in a more secure fashion by pointing ea...
As the number of available static analysis security testing (SAST) tools grows, the more difficult i...
This slide deck covers the differences between static (SAST) and dynamic (DAST) application security...
To improve the security of IT systems, companies can use automated security testing. In this thesis,...
This work presents a methodological approach to comparison of static security code analyzers. It sub...
Software vulnerabilities have been a significant attack surface used in cyberattacks, which have be...
Bakgrund I dagens programvara finns det problem som försämrar kvaliteten hos system och ökar kostnad...
Military systems typically run on isolated networks, which are typically secured at the physical lev...
U ovom radu proučene su tehnike te načini na koji općenito rade alati za statičku analizu koda koji ...
Security deficiencies that occur in web applications can have major consequences. PHP is a language ...
Esta tesis presenta una revisión general del estado de las herramientas de análisis de código estáti...
Static Application Security Testing Tools (SAST) is a security tool that claims to help with securit...
Static Application Security Testing (SAST) is a popular quality assurance technique in software engi...
Security testing is a widely applied measure to evaluate and improve software security by identifyin...
Abstract—Modern web applications play a pivotal role in our digital society. Motivated by the many s...
The goal of SAST-tools is to help developers coding software in a more secure fashion by pointing ea...
As the number of available static analysis security testing (SAST) tools grows, the more difficult i...
This slide deck covers the differences between static (SAST) and dynamic (DAST) application security...
To improve the security of IT systems, companies can use automated security testing. In this thesis,...
This work presents a methodological approach to comparison of static security code analyzers. It sub...
Software vulnerabilities have been a significant attack surface used in cyberattacks, which have be...
Bakgrund I dagens programvara finns det problem som försämrar kvaliteten hos system och ökar kostnad...
Military systems typically run on isolated networks, which are typically secured at the physical lev...
U ovom radu proučene su tehnike te načini na koji općenito rade alati za statičku analizu koda koji ...
Security deficiencies that occur in web applications can have major consequences. PHP is a language ...
Esta tesis presenta una revisión general del estado de las herramientas de análisis de código estáti...