Actas de congresos
Coverage Metrics And Detection Of Injection Vulnerabilities: An Experimental Study
Registro en:
978-1-5090-1582-5
2016 12th European Dependable Computing Conference (edcc 2016). Ieee, p. 45 - 52, 2016.
WOS:000390696300005
10.1109/EDCC.2016.32
Autor
Sayuri Matsunaga
Ana Paula; Antunes
Nuno; Moraes
Regina
Institución
Resumen
Coverage is frequently considered a metric of the quality of the tests and, consequently, of the software dependability. Although one tends to assume a similar relation in the context of vulnerability detection, such assumption is yet to be shown in practice. Although the effectiveness of vulnerability detection tools is limited and largely dependent on the context, developers usually select and use a single tool and implicitly trust on its results. In this practical experience report we study the relation between coverage measurements and the quality of the results of detection tests for injection vulnerabilities, in particular SQL Injection, considering two state of the art tools and multiple testing configurations. Such relation is of utmost importance for developers to understand how good vulnerability detectors are and to compare alternative tools. Results show that code coverage is indeed an effective mean to estimate the quality of vulnerability detection tests and is useful to compare different sets of tests. However, they also show that domain specific metrics are much more effective than generic ones. 45 52 12th European Dependable Computing Conference (EDCC) SEP 05-09, 2016 Gothenburg, SWEDEN