ECOOP and ISSTA 2018 (series) / Posters / Transparent Static Analysis for the Detection of Security Vulnerabilities
Transparent Static Analysis for the Detection of Security VulnerabilitiesDoctoral symposium paper
Static code analysis is a technology to automatically detect various security vulnerabilities at implementation time. Nevertheless, studies show that developers reject static analysis tools. The reason is that developers struggle to configure the static analysis such that it can operate efficiently in their application context. In this work, we improve the current situation by making the domain of static code analysis more transparent to developers when they use static analysis tools. In our approach, we propose a generator of configurations for static analyses for specific vulnerabilities selected by the developer. Moreover, the configurations are automatically customized to the code of interest that the developer works on.
Wed 18 JulDisplayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
Wed 18 Jul
Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change