New Version, New Answer: Investigating Cybersecurity Static-Analysis Tool Findings

New Version, New Answer: Investigating Cybersecurity Static-Analysis Tool Findings
复制标题

DOI:
10.1109/csr57506.2023.10224930
复制
发表时间:
2023-07
期刊:
2023 IEEE International Conference on Cyber Security and Resilience (CSR)
影响因子:
--
通讯作者:
A. Reinhold;Travis Weber;Colleen Lemak;Derek Reimanis;C. Izurieta
A. Reinhold;Travis Weber;Colleen Lemak;Derek Reimanis;C. Izurieta
中科院分区:
其他
文献类型:
--
作者:
A. Reinhold;Travis Weber;Colleen Lemak;Derek Reimanis;C. Izurieta

文献摘要

相似文献

自动检测二进制代码中的漏洞和弱点是网络安全研究前沿的迫切需要。网络安全静态分析工具旨在检测和列举漏洞和弱点。两个流行的工具是CVE二进制工具(CVE-bin-Tool)和CWE-Checker。Cve-bin-Tool使用通用漏洞和暴露(CVE)报告漏洞,而CWE-Checker使用通用漏洞枚举(CWE)报告漏洞。尽管广泛使用,但这些工具报告漏洞和弱点(在此称为“发现”)的一致性并未得到解决。我们对来自Kali Linux发行版的660个唯一二进制文件进行了系统调查,使用多个版本的静态分析工具对每个二进制文件进行了评估,并调查了结果如何随使用的静态分析工具的版本而变化。我们预计结果会随着软件开发生命周期的不同而有所不同。然而,不同版本报告的结果变化的数量和幅度都是巨大的。新版本给出了新的答案。
Automated detection of vulnerabilities and weaknesses in binary code is a critical need at the frontier of cybersecurity research. Cybersecurity static-analysis tools aim to detect and enumerate vulnerabilities and weaknesses. Two popular tools are CVE Binary Tool (cve-bin-tool) and cwe-checker. Cve-bin-tool reports vulnerabilities using Common Vulnerabilities and Exposures (CVE) whereas cwe-checker reports weaknesses using Common Weakness Enumeration (CWE). Despite widespread use, the consistency with which these tools report vulnerabilities and weaknesses (herein, “findings”) was unaddressed. We conducted a systematic investigation of 660 unique binaries taken from a Kali Linux distribution, evaluated each binary with multiple versions of the static-analysis tools, and investigated how the findings changed according to the version of the static-analysis tool used. We expected some variation in findings commensurate with the software-development life cycle. However, the number and magnitude of the changes in findings reported across versions were substantial. New versions gave new answers.