Benchmarking the vulnerability detection capabilities of software analysis tools

Publication date

2022

Authors

Baninemeh, ElenaISNI 000000051776213X
Jansen, R.L.ORCID 0000-0003-3752-2868ISNI 000000039050399X

Editors

Advisors

Supervisors

DOI

Document Type

/dk/atira/pure/researchoutput/researchoutputtypes/contributiontojournal/conferencearticle
Open Access logo

License

cc_by

Abstract

Code cloning and copy-pasting code fragments is common practice in software engineering. If security vulnerabilities exist in a cloned code segment, those vulnerabilities may spread in the related software, potentially leading to security incidents. Code similarity is one effective approach to detect vulnerabilities hidden in software projects. However, due to the complexity, size, and diversity of source code, current methods suffer from low accuracy, and poor performance. Moreover, most existing clone detection techniques focus on a limited set of programming languages in the detection process. We propose to solve these problems using SearchSECO, a software analysis tool that detects vulnerabilities in multiple programming languages.

Keywords

code clone detection, open-source software, software security, Software vulnerability, General Computer Science

Citation

Baninemeh, E & Jansen, S 2022, 'Benchmarking the vulnerability detection capabilities of software analysis tools', CEUR Workshop Proceedings, vol. 3245. < https://ceur-ws.org/Vol-3245/ >