Vulnerabilities mapping based on OWASP-SANS: a survey for Static Application Security Testing (SAST)
File(s)p1.pdf (1.21 MB)
Published version
OA Location
Author(s)
Li, Jinfeng
Type
Journal Article
Abstract
The delivery of a framework in place for secure application development is of real value for application development teams to integrate security into their development life cycle, especially when a mobile or web application moves past the scanning stage and focuses increasingly on the remediation or mitigation phase based on static application security testing(SAST). For the first time, to the author’s knowledge, the industry-standard Open Web Application Security Project(OWASP)top 10 vulnerabilities and CWE/SANS top 25 most dangerous software errors are synced up in a matrix with Checkmarx vulnerability queries, producing anapplication security framework that helps development teams review and address code vulnerabilities, minimise false positives discovered in static scans and penetration tests, targeting an increased accuracy of the findings. A case study is conducted for vulnerabilities scanning of a proof-of-concept mobile malware detection app. Mapping the OWASP/SANS with Check marx vulnerabilities queries,flaws and vulnerabilities are demonstrated to be mitigated with improved efficiency.
Date Issued
2020-07-01
Date Acceptance
2020-04-07
Citation
Annals of Emerging Technologies in Computing (AETiC), 2020, 4 (3), pp.1-8
ISSN
2516-0281
Publisher
Annals of Emerging Technologies in Computing (AETiC)
Start Page
1
End Page
8
Journal / Book Title
Annals of Emerging Technologies in Computing (AETiC)
Volume
4
Issue
3
Copyright Statement
© 2020 by the author. Published by Annals of Emerging Technologies in Computing
(AETiC), under the terms and conditions of the Creative Commons Attribution (CC BY)
license which can be accessed at http://creativecommons.org/licenses/by/4.0.
(AETiC), under the terms and conditions of the Creative Commons Attribution (CC BY)
license which can be accessed at http://creativecommons.org/licenses/by/4.0.
License URL
Identifier
http://aetic.theiaer.org/archive/v4/v4n3/p1.html
Subjects
cs.CR
cs.CR
cs.SE
Publication Status
Accepted
Date Publish Online
2020-07-01