The Experts below are selected from a list of 96 Experts worldwide ranked by ideXlab platform
Juan Ramón Bermejo - One of the best experts on this subject based on the ideXlab platform.
-
Static analysis of source code security
Information & Software Technology, 2013Co-Authors: Gabriel Diaz, Juan Ramón BermejoAbstract:ContextStatic analysis tools are used to discover security vulnerabilities in source code. They suffer from false negatives and false positives. A false positive is a Reported Vulnerability in a program that is not really a security problem. A false negative is a Vulnerability in the code which is not detected by the tool. ObjectiveThe main goal of this article is to provide objective assessment results following a well-defined and repeatable methodology that analyzes the performance detecting security vulnerabilities of static analysis tools. The study compares the performance of nine tools (CBMC, K8-Insight, PC-lint, Prevent, Satabs, SCA, Goanna, Cx-enterprise, Codesonar), most of them commercials tools, having a different design. MethodWe executed the static analysis tools against SAMATE Reference Dataset test suites 45 and 46 for C language. One includes test cases with known vulnerabilities and the other one is designed with specific vulnerabilities fixed. Afterwards, the results are analyzed by using a set of well known metrics. ResultsOnly SCA is designed to detect all vulnerabilities considered in SAMATE. None of the tools detect "cross-site scripting" vulnerabilities. The best results for F-measure metric are obtained by Prevent, SCA and K8-Insight. The average precision for analyzed tools is 0.7 and the average recall is 0.527. The differences between all tools are relevant, detecting different kinds of vulnerabilities. ConclusionsThe results provide empirical evidences that support popular propositions not objectively demonstrated until now. The methodology is repeatable and allows ranking strictly the analyzed static analysis tools, in terms of vulnerabilities coverage and effectiveness for detecting the highest number of vulnerabilities having few false positives. Its use can help practitioners to select appropriate tools for a security review process of code. We propose some recommendations for improving the reliability and usefulness of static analysis tools and the process of benchmarking.
-
Static analysis of source code security: Assessment of tools against SAMATE tests
Information and Software Technology, 2013Co-Authors: Gabriel Diaz, Juan Ramón BermejoAbstract:Context: Static analysis tools are used to discover security vulnerabilities in source code. They suffer from false negatives and false positives. A false positive is a Reported Vulnerability in a program that is not really a security problem. A false negative is a Vulnerability in the code which is not detected by the tool. Objective: The main goal of this article is to provide objective assessment results following a well-defined and repeatable methodology that analyzes the performance detecting security vulnerabilities of static analysis tools. The study compares the performance of nine tools (CBMC, K8-Insight, PC-lint, Prevent, Satabs, SCA, Goanna, Cx-enterprise, Codesonar), most of them commercials tools, having a different design. Method: We executed the static analysis tools against SAMATE Reference Dataset test suites 45 and 46 for C language. One includes test cases with known vulnerabilities and the other one is designed with specific vulnerabilities fixed. Afterwards, the results are analyzed by using a set of well known metrics. Results: Only SCA is designed to detect all vulnerabilities considered in SAMATE. None of the tools detect "cross-site scripting" vulnerabilities. The best results for F-measure metric are obtained by Prevent, SCA and K8-Insight. The average precision for analyzed tools is 0.7 and the average recall is 0.527. The differences between all tools are relevant, detecting different kinds of vulnerabilities. Conclusions: The results provide empirical evidences that support popular propositions not objectively demonstrated until now. The methodology is repeatable and allows ranking strictly the analyzed static analysis tools, in terms of vulnerabilities coverage and effectiveness for detecting the highest number of vulnerabilities having few false positives. Its use can help practitioners to select appropriate tools for a security review process of code. We propose some recommendations for improving the reliability and usefulness of static analysis tools and the process of benchmarking. © 2013 Elsevier B.V. All rights reserved.
Gabriel Diaz - One of the best experts on this subject based on the ideXlab platform.
-
Static analysis of source code security
Information & Software Technology, 2013Co-Authors: Gabriel Diaz, Juan Ramón BermejoAbstract:ContextStatic analysis tools are used to discover security vulnerabilities in source code. They suffer from false negatives and false positives. A false positive is a Reported Vulnerability in a program that is not really a security problem. A false negative is a Vulnerability in the code which is not detected by the tool. ObjectiveThe main goal of this article is to provide objective assessment results following a well-defined and repeatable methodology that analyzes the performance detecting security vulnerabilities of static analysis tools. The study compares the performance of nine tools (CBMC, K8-Insight, PC-lint, Prevent, Satabs, SCA, Goanna, Cx-enterprise, Codesonar), most of them commercials tools, having a different design. MethodWe executed the static analysis tools against SAMATE Reference Dataset test suites 45 and 46 for C language. One includes test cases with known vulnerabilities and the other one is designed with specific vulnerabilities fixed. Afterwards, the results are analyzed by using a set of well known metrics. ResultsOnly SCA is designed to detect all vulnerabilities considered in SAMATE. None of the tools detect "cross-site scripting" vulnerabilities. The best results for F-measure metric are obtained by Prevent, SCA and K8-Insight. The average precision for analyzed tools is 0.7 and the average recall is 0.527. The differences between all tools are relevant, detecting different kinds of vulnerabilities. ConclusionsThe results provide empirical evidences that support popular propositions not objectively demonstrated until now. The methodology is repeatable and allows ranking strictly the analyzed static analysis tools, in terms of vulnerabilities coverage and effectiveness for detecting the highest number of vulnerabilities having few false positives. Its use can help practitioners to select appropriate tools for a security review process of code. We propose some recommendations for improving the reliability and usefulness of static analysis tools and the process of benchmarking.
-
Static analysis of source code security: Assessment of tools against SAMATE tests
Information and Software Technology, 2013Co-Authors: Gabriel Diaz, Juan Ramón BermejoAbstract:Context: Static analysis tools are used to discover security vulnerabilities in source code. They suffer from false negatives and false positives. A false positive is a Reported Vulnerability in a program that is not really a security problem. A false negative is a Vulnerability in the code which is not detected by the tool. Objective: The main goal of this article is to provide objective assessment results following a well-defined and repeatable methodology that analyzes the performance detecting security vulnerabilities of static analysis tools. The study compares the performance of nine tools (CBMC, K8-Insight, PC-lint, Prevent, Satabs, SCA, Goanna, Cx-enterprise, Codesonar), most of them commercials tools, having a different design. Method: We executed the static analysis tools against SAMATE Reference Dataset test suites 45 and 46 for C language. One includes test cases with known vulnerabilities and the other one is designed with specific vulnerabilities fixed. Afterwards, the results are analyzed by using a set of well known metrics. Results: Only SCA is designed to detect all vulnerabilities considered in SAMATE. None of the tools detect "cross-site scripting" vulnerabilities. The best results for F-measure metric are obtained by Prevent, SCA and K8-Insight. The average precision for analyzed tools is 0.7 and the average recall is 0.527. The differences between all tools are relevant, detecting different kinds of vulnerabilities. Conclusions: The results provide empirical evidences that support popular propositions not objectively demonstrated until now. The methodology is repeatable and allows ranking strictly the analyzed static analysis tools, in terms of vulnerabilities coverage and effectiveness for detecting the highest number of vulnerabilities having few false positives. Its use can help practitioners to select appropriate tools for a security review process of code. We propose some recommendations for improving the reliability and usefulness of static analysis tools and the process of benchmarking. © 2013 Elsevier B.V. All rights reserved.
J R Eiser - One of the best experts on this subject based on the ideXlab platform.
-
Skin cancer attitudes: a cross-national comparison.
The British journal of social psychology, 1995Co-Authors: J R Eiser, C Eiser, F Sani, L Sell, R M CasasAbstract:A questionnaire concerning attitudes towards skin cancer, sun exposure and general environmental issues was administered to 132 holiday-makers on a beach in south-west England and (in translation) to 142 visitors to another beach in north-west Italy. Following the Janis & Mann (1977) classification of strategies for coping with decision conflicts, subscales were derived measuring tendencies to 'avoid' thinking about environmental issues, to 'bolster' prior attitudes (by playing down the seriousness of the risk of skin cancer while attending to the pleasures of sunbathing), and to be 'vigilant' concerning risk information and the need for specific protective behaviour (e.g. sunscreen use). The British scored higher than the Italians, and women higher than men, on vigilance, but there were no gender or nationality differences on the other subscales considered as a whole. Responses were also related to the covariates of age and self-Reported Vulnerability to sunburn. Those who showed less concern with environmental issues also tended to play down the risks of skin cancer and be less vigilant with regard to self-protection. It is suggested that health promotion should address both cultural norms concerning exposure to the sun and people's intuitive notions about their relative personal Vulnerability.
-
Skin cancer attitudes: A cross‐national comparison
British Journal of Social Psychology, 1995Co-Authors: J R Eiser, C Eiser, F Sani, L Sell, Rosa CasasAbstract:: A questionnaire concerning attitudes towards skin cancer, sun exposure and general environmental issues was administered to 132 holiday-makers on a beach in south-west England and (in translation) to 142 visitors to another beach in north-west Italy. Following the Janis & Mann (1977) classification of strategies for coping with decision conflicts, subscales were derived measuring tendencies to 'avoid' thinking about environmental issues, to 'bolster' prior attitudes (by playing down the seriousness of the risk of skin cancer while attending to the pleasures of sunbathing), and to be 'vigilant' concerning risk information and the need for specific protective behaviour (e.g. sunscreen use). The British scored higher than the Italians, and women higher than men, on vigilance, but there were no gender or nationality differences on the other subscales considered as a whole. Responses were also related to the covariates of age and self-Reported Vulnerability to sunburn. Those who showed less concern with environmental issues also tended to play down the risks of skin cancer and be less vigilant with regard to self-protection. It is suggested that health promotion should address both cultural norms concerning exposure to the sun and people's intuitive notions about their relative personal Vulnerability.
Hao Xu - One of the best experts on this subject based on the ideXlab platform.
-
HICSS - Economic analysis of the market for software Vulnerability disclosure
37th Annual Hawaii International Conference on System Sciences 2004. Proceedings of the, 2004Co-Authors: K. Kannan, Rahul Telang, Hao XuAbstract:Software Vulnerability identification and their disclosure has been a critical area of concern for policy makers. Traditionally, computer emergency response team (CERT) has been acting as an infomediary between benign identifiers who report Vulnerability information and users of the software. After verifying a Reported Vulnerability, and obtaining the remediation in the form of a patch from the software vendor, the infomediary - CERT - sends out a public "advisory" to inform software users about it. In the CERT type mechanism, reporting vulnerabilities is voluntary with no explicit monetary gains to benign identifiers. Of late, firms such as iDefense have been proposing a different market based mechanism. In this market based mechanism, the infomediary rewards identifiers for each Vulnerability disclosed to it. The infomediary then shares this information with its clients who are users of this software. Using this information, clients can protect themselves against attacks that exploit those specific vulnerabilities. The key issue addressed in this paper is whether movement towards such a market based mechanism for vulnerabilities leads to a better social outcome? We study this problem by characterizing the behavior of software users benign and malign identifiers (or hackers).
-
Economic analysis of the market for software Vulnerability disclosure
37th Annual Hawaii International Conference on System Sciences 2004. Proceedings of the, 2004Co-Authors: K. Kannan, Rahul Telang, Hao XuAbstract:Software Vulnerability identification and their disclosure has been a critical area of concern for policy makers. Traditionally, computer emergency response team (CERT) has been acting as an infomediary between benign identifiers who report Vulnerability information and users of the software. After verifying a Reported Vulnerability, and obtaining the remediation in the form of a patch from the software vendor, the infomediary - CERT - sends out a public "advisory" to inform software users about it. In the CERT type mechanism, reporting vulnerabilities is voluntary with no explicit monetary gains to benign identifiers. Of late, firms such as iDefense have been proposing a different market based mechanism. In this market based mechanism, the infomediary rewards identifiers for each Vulnerability disclosed to it. The infomediary then shares this information with its clients who are users of this software. Using this information, clients can protect themselves against attacks that exploit those specific vulnerabilities. The key issue addressed in this paper is whether movement towards such a market based mechanism for vulnerabilities leads to a better social outcome? We study this problem by characterizing the behavior of software users benign and malign identifiers (or hackers).
K. Kannan - One of the best experts on this subject based on the ideXlab platform.
-
An Economic Analysis of Market for Software Vulnerabilities
2020Co-Authors: K. Kannan, Rahul TelangAbstract:Software Vulnerability disclosure has become a critical area of concern for policy-makers. Traditionally, Computer Emergency Response Team (CERT) has been acting as an infomediary between benign identifiers (who report Vulnerability information voluntarily) and software users. After verifying a Reported Vulnerability, the infomediary – CERT – sends out a public “advisory” so that users can safeguard their systems against potential exploits. Of late, firms such as iDefense have been implementing a different market-based approach for Vulnerability disclosure where the “market-based” infomediary provides monetary rewards to identifiers for each Vulnerability disclosed to it. The infomediary shares this information with its client base. Using this information, clients protect themselves against attacks that exploit those specific vulnerabilities. The key question addressed in our paper is whether movement towards such a market-based mechanism for Vulnerability disclosure leads to a better social outcome. Our analysis demonstrates that an active “market-based mechanism” for vulnerabilities almost always underperforms a passive CERT-type mechanism. We provide intuitions to this counter-intuitive result. Further, our paper provides policy recommendations that improve the relative performance of the market-based mechanism though not completely. Finally, we extend our analysis and analyze a new mechanism – “Federally-Funded Social Planner” – that always performs better than a market-based mechanism.
-
Market for Software Vulnerabilities? Think Again
Management Science, 2005Co-Authors: K. Kannan, Rahul TelangAbstract:Software Vulnerability disclosure has become a critical area of concern for policymakers. Traditionally, a Computer Emergency Response Team (CERT) acts as an infomediary between benign identifiers (who voluntarily report Vulnerability information) and software users. After verifying a Reported Vulnerability, CERT sends out a public advisory so that users can safeguard their systems against potential exploits. Lately, firms such as iDefense have been implementing a new market-based approach for Vulnerability information. The market-based infomediary provides monetary rewards to identifiers for each Vulnerability Reported. The infomediary then shares this information with its client base. Using this information, clients protect themselves against potential attacks that exploit those specific vulnerabilities.The key question addressed in our paper is whether movement toward such a market-based mechanism for Vulnerability disclosure leads to a better social outcome. Our analysis demonstrates that an active unregulated market-based mechanism for vulnerabilities almost always underperforms a passive CERT-type mechanism. This counterintuitive result is attributed to the market-based infomediary's incentive to leak the Vulnerability information inappropriately. If a profit-maximizing firm is not allowed to (or chooses not to) leak Vulnerability information, we find that social welfare improves. Even a regulated market-based mechanism performs better than a CERT-type one, but only under certain conditions. Finally, we extend our analysis and show that a proposed mechanism--federally funded social planner--always performs better than a market-based mechanism.
-
HICSS - Economic analysis of the market for software Vulnerability disclosure
37th Annual Hawaii International Conference on System Sciences 2004. Proceedings of the, 2004Co-Authors: K. Kannan, Rahul Telang, Hao XuAbstract:Software Vulnerability identification and their disclosure has been a critical area of concern for policy makers. Traditionally, computer emergency response team (CERT) has been acting as an infomediary between benign identifiers who report Vulnerability information and users of the software. After verifying a Reported Vulnerability, and obtaining the remediation in the form of a patch from the software vendor, the infomediary - CERT - sends out a public "advisory" to inform software users about it. In the CERT type mechanism, reporting vulnerabilities is voluntary with no explicit monetary gains to benign identifiers. Of late, firms such as iDefense have been proposing a different market based mechanism. In this market based mechanism, the infomediary rewards identifiers for each Vulnerability disclosed to it. The infomediary then shares this information with its clients who are users of this software. Using this information, clients can protect themselves against attacks that exploit those specific vulnerabilities. The key issue addressed in this paper is whether movement towards such a market based mechanism for vulnerabilities leads to a better social outcome? We study this problem by characterizing the behavior of software users benign and malign identifiers (or hackers).
-
Economic analysis of the market for software Vulnerability disclosure
37th Annual Hawaii International Conference on System Sciences 2004. Proceedings of the, 2004Co-Authors: K. Kannan, Rahul Telang, Hao XuAbstract:Software Vulnerability identification and their disclosure has been a critical area of concern for policy makers. Traditionally, computer emergency response team (CERT) has been acting as an infomediary between benign identifiers who report Vulnerability information and users of the software. After verifying a Reported Vulnerability, and obtaining the remediation in the form of a patch from the software vendor, the infomediary - CERT - sends out a public "advisory" to inform software users about it. In the CERT type mechanism, reporting vulnerabilities is voluntary with no explicit monetary gains to benign identifiers. Of late, firms such as iDefense have been proposing a different market based mechanism. In this market based mechanism, the infomediary rewards identifiers for each Vulnerability disclosed to it. The infomediary then shares this information with its clients who are users of this software. Using this information, clients can protect themselves against attacks that exploit those specific vulnerabilities. The key issue addressed in this paper is whether movement towards such a market based mechanism for vulnerabilities leads to a better social outcome? We study this problem by characterizing the behavior of software users benign and malign identifiers (or hackers).