TUHH Open Research
Help
  • Log In
    New user? Click here to register.Have you forgotten your password?
  • English
  • Deutsch
  • Communities & Collections
  • Publications
  • Research Data
  • People
  • Institutions
  • Projects
  • Statistics
  1. Home
  2. TUHH
  3. Publication References
  4. Static analysis and penetration testing from the perspective of maintenance teams
 
Options

Static analysis and penetration testing from the perspective of maintenance teams

Publikationstyp
Conference Paper
Date Issued
2016-09
Sprache
English
Author(s)
Ceccato, Mariano  
Scandariato, Riccardo  
TORE-URI
http://hdl.handle.net/11420/14422
First published in
International Symposium on Empirical Software Engineering and Measurement  
Number in series
8/9
Article Number
a25
Citation
International Symposium on Empirical Software Engineering and Measurement 8/9: a25 (2016)
Contribution to Conference
10th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement, ESEM 2016  
Publisher DOI
10.1145/2961111.2962611
Scopus ID
2-s2.0-84991705991
Publisher
ACM
ISBN
978-1-4503-4427-2
ISBN of container
978-1-4503-4427-2
Static analysis and penetration testing are common techniques used to discover security bugs in implementation code. Penetration testing is often performed in black-box way by probing the attack surface of a running system and discovering its security holes. Static analysis techniques operate in a white-box way by analyzing the source code of a system and identifying security weaknesses. Because of their different nature, the two techniques report their findings in two different ways. This paper presents an exploratory study meant to determine whether a vulnerability report generated by a security tool based on static analysis is more or less useful than a report generated by a security tool based on penetration testing. The usefulness is judged from the perspective of the developers that have to devise a vulnerability-fixing patch. The initial results show an advantage when using penetration testing in one of the two cases we investigated.
Subjects
Penetration testing
Software maintenance
Static analysis
DDC Class
004: Informatik
TUHH
Weiterführende Links
  • Contact
  • Send Feedback
  • Cookie settings
  • Privacy policy
  • Impress
DSpace Software

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science
Design by effective webwork GmbH

  • Deutsche NationalbibliothekDeutsche Nationalbibliothek
  • ORCiD Member OrganizationORCiD Member Organization
  • DataCiteDataCite
  • Re3DataRe3Data
  • OpenDOAROpenDOAR
  • OpenAireOpenAire
  • BASE Bielefeld Academic Search EngineBASE Bielefeld Academic Search Engine
Feedback