REVIEW 1 cited by
Evaluation of Static Analysis Tools for Finding Vulnerabilities in Java and C/C++ Source Code
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
It is quite common for security testing to be delayed until after the software has been developed, but vulnerabilities may get noticed throughout the implementation phase and the earlier they are discovered, the easier and cheaper it will be to fix them. Software development processes such as the secure software development lifecycle incorporates security at every stage of the design and development process. Static code scanning tools find vulnerabilities in code by highlighting potential security flaws and offer examples on how to resolve them, and some may even modify the code to remove the susceptibility. This paper compares static analysis tools for Java and C/C++ source code, and explores their pros and cons.
Forward citations
Cited by 1 Pith paper
-
SoK: Where to Fuzz? Assessing Target Selection Methods in Directed Fuzzing
Simple code metrics, especially Leopard's vulnerability scores, retrieve crash-relevant functions more accurately than sanitizer heuristics, recently-changed code, or deep learning models on a corpus of 1,621 real crashes.
Discussion (0). Continue with ORCID to comment.