dc.creatorSayuri Matsunaga
dc.creatorAna Paula; Antunes
dc.creatorNuno; Moraes
dc.creatorRegina
dc.date2016
dc.date2017-11-13T13:50:46Z
dc.date2017-11-13T13:50:46Z
dc.date.accessioned2018-03-29T06:07:17Z
dc.date.available2018-03-29T06:07:17Z
dc.identifier978-1-5090-1582-5
dc.identifier2016 12th European Dependable Computing Conference (edcc 2016). Ieee, p. 45 - 52, 2016.
dc.identifierWOS:000390696300005
dc.identifier10.1109/EDCC.2016.32
dc.identifierhttp://ieeexplore.ieee.org/document/7780344/
dc.identifierhttp://repositorio.unicamp.br/jspui/handle/REPOSIP/329268
dc.identifier.urihttp://repositorioslatinoamericanos.uchile.cl/handle/2250/1366293
dc.descriptionCoverage is frequently considered a metric of the quality of the tests and, consequently, of the software dependability. Although one tends to assume a similar relation in the context of vulnerability detection, such assumption is yet to be shown in practice. Although the effectiveness of vulnerability detection tools is limited and largely dependent on the context, developers usually select and use a single tool and implicitly trust on its results. In this practical experience report we study the relation between coverage measurements and the quality of the results of detection tests for injection vulnerabilities, in particular SQL Injection, considering two state of the art tools and multiple testing configurations. Such relation is of utmost importance for developers to understand how good vulnerability detectors are and to compare alternative tools. Results show that code coverage is indeed an effective mean to estimate the quality of vulnerability detection tests and is useful to compare different sets of tests. However, they also show that domain specific metrics are much more effective than generic ones.
dc.description45
dc.description52
dc.description12th European Dependable Computing Conference (EDCC)
dc.descriptionSEP 05-09, 2016
dc.descriptionGothenburg, SWEDEN
dc.languageEnglish
dc.publisherIEEE
dc.publisherNew York
dc.relation2016 12th European Dependable Computing Conference (EDCC 2016)
dc.rightsfechado
dc.sourceWOS
dc.subjectVulnerability Detection
dc.subjectCode Coverage
dc.subjectTool Trustworthiness
dc.subjectBenchmarking
dc.titleCoverage Metrics And Detection Of Injection Vulnerabilities: An Experimental Study
dc.typeActas de congresos


Este ítem pertenece a la siguiente institución