Static analysis versus penetration testing: A controlled experiment

Static analysis versus penetration testing: A controlled experiment
复制标题

静态分析与渗透测试:受控实验

DOI:
10.1109/issre.2013.6698898
复制
发表时间:
2013
期刊:
2013 IEEE 24th International Symposium on Software Reliability Engineering (ISSRE)
影响因子:
--
通讯作者:
W. Joosen
W. Joosen
中科院分区:
--
文献类型:
--
作者:
R. Scandariato;J. Walden;W. Joosen

文献摘要

被引文献

相似文献

假设您必须组建一个安全团队,该团队的任务是对组织的最新应用程序执行安全分析。在研究了如何评估您的应用程序之后,您会发现最流行的技术(也由大多数安全咨询公司提供)是自动静态分析和黑盒渗透测试。在时间和预算的限制下,你会先使用哪一种技术?本文通过探索性控制实验比较了这两种技术,其中9名参与者分析了两个开源博客应用程序的安全性。尽管它的规模相对较小,但该研究表明,静态分析比渗透测试在更短的时间内发现了更多的漏洞。
Suppose you have to assemble a security team, which is tasked with performing the security analysis of your organization's latest applications. After researching how to assess your applications, you find that the most popular techniques (also offered by most security consultancies) are automated static analysis and black box penetration testing. Under time and budget constraints, which technique would you use first? This paper compares these two techniques by means of an exploratory controlled experiment, in which 9 participants analyzed the security of two open source blogging applications. Despite its relative small size, this study shows that static analysis finds more vulnerabilities and in a shorter time than penetration testing.