ESEIW 2024
Sun 20 - Fri 25 October 2024 Barcelona, Spain
Thu 24 Oct 2024 12:15 - 12:30 at Sala de graus (C4 Building) - Software testing Chair(s): Marco Torchiano

Vulnerabilities are a serious threat to a system and to its users. Static application Security Testing (SAST) tools are an established means to detect vulnerabilities early in development. Previous studies report low detection rates from SAST tools, and recommend either combining multiple SAST tools, or configuring rule sets to detect significantly more vulnerabilities. However, previous work suggests that developers rarely combine or configure any of the Automatic Static Analysis Tools (ASATs) that they use, but it is currently unknown whether SAST tools are also used directly out of the box. To understand how developers use and configure SAST tools, we perform a large-scale survey involving 1,263 developers. We prescreen developers to establish their SAST use and find only 20.3% (204/1,003) use SAST tools, far fewer than are reported to use ASATs. Of those developers who do use SAST tools, we find the majority do not combine multiple tools (97/175), do not configure their tools (89/175), and a large number do neither (65/175). Our results suggest that more work is needed to assist developers in combining and configuring tools, as doing so is likely to detect significantly more vulnerabilities.

Thu 24 Oct

Displayed time zone: Brussels, Copenhagen, Madrid, Paris change

11:00 - 12:30
11:00
20m
Full-paper
Automatic Data Labeling for Software Vulnerability Prediction Models: How Far Are We?
ESEM Technical Papers
Triet Le The University of Adelaide, Muhammad Ali Babar School of Computer Science, The University of Adelaide
11:20
20m
Full-paper
Contexts Matter: An Empirical Study on Contextual Influence in Fairness Testing for Deep Learning Systems
ESEM Technical Papers
Chengwen Du University of Birmingham, Tao Chen University of Birmingham
11:40
20m
Full-paper
Mitigating Data Imbalance for Software Vulnerability Assessment: Does Data Augmentation Help?
ESEM Technical Papers
Triet Le The University of Adelaide, Muhammad Ali Babar School of Computer Science, The University of Adelaide
12:00
15m
Industry talk
From Literature to Practice: Exploring Fairness Testing Tools for the Software Industry Adoption
ESEM IGC
Thanh Nguyen University of Calgary, Maria Teresa Baldassarre Department of Computer Science, University of Bari , Luiz Fernando de Lima , Ronnie de Souza Santos University of Calgary
Pre-print
12:15
15m
Vision and Emerging Results
Do Developers Use Static Application Security Testing (SAST) Tools Straight Out of the Box? A large-scale Empirical Study
ESEM Emerging Results, Vision and Reflection Papers Track
Gareth Bennett Lancaster University, Tracy Hall Lancaster University, Steve Counsell Brunel University London, Emily Winter Lancaster University, Thomas Shippey LogicMonitor