Automatic repair of OWASP Top 10 security vulnerabilities: A survey


연구 분야: Infrastructure



학회: ICSEW'20: Proceedings of the IEEE/ACM 42nd International Conference on Software Engineering Workshops


초록

Current work on automatic program repair has not focused on actually prevalent vulnerabilities in web applications, such as described in the OWASP Top 10 categories, leading to a scarcely explored field, which in turn leads to a gap between industry needs and research efforts. In order to assess the extent of this gap, we have surveyed and analyzed the literature on fully automatic source-code manipulating program repair of OWASP Top 10 vulnerabilities, as well as their corresponding test suites. We find that there is a significant gap in the coverage of the OWASP Top 10 vulnerabilities, and that the test suites used to test the analyzed approaches are highly inadequate. Few approaches cover multiple OWASP Top 10 vulnerabilities, and there is no combination of existing test suites that achieves a total coverage of OWASP Top 10.


Author Profile
Alexander Marchand-Melsom

Norwegian University of Science and Technology Trondheim Norway

Andorra
Author Profile
Duong Bao Nguyen Mai

Norwegian University of Science and Technology Trondheim Norway

Andorra

📄 논문 정보

발행 연도 2020년
인용수 10
출판 국가 Andorra
사이트 ACM
좋아요 수 0

연관 논문 목록 (136건)