One Technique is Not Enough: A Comparison of Vulnerability Discovery Techniques

One Technique is Not Enough: A Comparison of Vulnerability Discovery Techniques
复制标题

一种技术是不够的:漏洞发现技术的比较

DOI:
10.1109/esem.2011.18
复制
发表时间:
2011
期刊:
2011 International Symposium on Empirical Software Engineering and Measurement
影响因子:
--
通讯作者:
L. Williams
L. Williams
中科院分区:
--
文献类型:
--
作者:
Andrew Austin;L. Williams

文献摘要

被引文献

相似文献

在开发周期后期发现的安全漏洞比早期发现的漏洞修复成本更高。因此,软件开发人员应该努力尽早发现漏洞。不幸的是,庞大的代码库和开发人员专业知识的缺乏会使发现软件漏洞变得困难。为了减轻这个困难,已经设计了许多不同类型的技术来帮助开发人员发现漏洞。本研究的目的是通过比较漏洞发现技术的有效性来改进漏洞检测,并提供使用这些技术改进漏洞发现的具体建议。我们对两个电子健康记录系统进行了案例研究,以比较四种发现技术:系统和探索性手动渗透测试、静态分析和自动化渗透测试。在我们的案例研究中,我们发现经验证据表明,没有一种技术可以发现所有类型的漏洞。使用多种发现技术,我们几乎没有发现任何单独的漏洞。我们还发现,系统的人工渗透测试发现了最多的设计缺陷,而静态分析发现了最多的实现缺陷。最后,我们发现,就每小时发现的漏洞而言,最有效的漏洞发现技术是自动化渗透测试。这些结果表明,如果进行漏洞发现的时间有限,则应该进行自动渗透测试以发现实现错误,并进行系统的手动渗透测试以发现设计缺陷。
Security vulnerabilities discovered later in the development cycle are more expensive to fix than those discovered early. Therefore, software developers should strive to discover vulnerabilities as early as possible. Unfortunately, the large size of code bases and lack of developer expertise can make discovering software vulnerabilities difficult. To ease this difficulty, many different types of techniques have been devised to aid developers in vulnerability discovery. The goal of this research is to improve vulnerability detection by comparing the effectiveness of vulnerability discovery techniques and to provide specific recommendations to improve vulnerability discovery with these techniques. We conducted a case study on two electronic health record systems to compare four discovery techniques: systematic and exploratory manual penetration testing, static analysis, and automated penetration testing. In our case study, we found empirical evidence that no single technique discovered every type of vulnerability. We discovered almost no individual vulnerabilities with multiple discovery techniques. We also found that systematic manual penetration testing found the most design flaws, while static analysis found the most implementation bugs. Finally, we found the most effective vulnerability discovery technique in terms of vulnerabilities discovered per hour was automated penetration testing. These results suggest that if one has limited time to preform vulnerability discovery one should conduct automated penetration testing to discover implementation bugs and systematic manual penetration testing to discover design flaws.