Static analysis versus penetration testing: A controlled experiment
Static analysis versus penetration testing: A controlled experiment
复制标题
静态分析与渗透测试:受控实验
DOI:
10.1109/issre.2013.6698898
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
W. Joosen
中科院分区:
文献类型:
--
作者:
R. Scandariato;J. Walden;W. Joosen
Suppose you have to assemble a security team, which is tasked with performing the security analysis of your organization's latest applications. After researching how to assess your applications, you find that the most popular techniques (also offered by most security consultancies) are automated static analysis and black box penetration testing. Under time and budget constraints, which technique would you use first? This paper compares these two techniques by means of an exploratory controlled experiment, in which 9 participants analyzed the security of two open source blogging applications. Despite its relative small size, this study shows that static analysis finds more vulnerabilities and in a shorter time than penetration testing.