中文

使用 SonarCloud 代码分析的漏洞源代码检测

计算机与社会 2023-07-06 v1 密码学与安全

摘要

在软件开发生命周期(SDLC)中,安全漏洞是在构建阶段引入的问题之一。产品发布到市场后未能及早检测软件缺陷,会导致公司更高的修复成本。因此,它会降低公司声誉、侵犯用户隐私,并给应用带来无法修复的问题。漏洞检测的引入能够减少误报数量,从而将有限的测试精力集中在潜在存在漏洞的文件上。UMKM Masa Kini (UMI) 是一个用于销售任何微、小和中型企业产品(UMKM)的销售点应用。因此,在当前工作中,我们分析这些度量标准对于为 UMI 应用创建基于机器学习(ML)的软件漏洞检测器的适用性。代码使用商业工具 SonarCloud 生成。实验结果显示检测到了 3,285 条漏洞规则。

关键词

引用

@article{arxiv.2307.02446,
  title  = {Vulnerable Source Code Detection using SonarCloud Code Analysis},
  author = {Alifia Puspaningrum and Muhammad Anis Al Hilmi and Darsih and Muhamad Mustamiin and Maulana Ilham Ginanjar},
  journal= {arXiv preprint arXiv:2307.02446},
  year   = {2023}
}

备注

Paper entitled "#1570844450 ('Vulnerable Source Code Detection using SonarCloud Code Analysis')" is ACCEPTED as an oral or video presentation in the 5th International Conference on Applied Science Technology (ICAST-2022) https://icast.isas.or.id/2022/