Mostrar el registro sencillo del ítem

dc.contributor.authorBermejo Higuera, Juan Ramón
dc.contributor.authorBermejo-Higuera, Javier
dc.contributor.authorSicilia, Juan Antonio
dc.contributor.authorSureda Riera, Tomás
dc.contributor.authorArgyros, Christopher I.
dc.contributor.authorMagreñán, Á. Alberto
dc.date2021
dc.date.accessioned2022-03-28T10:28:09Z
dc.date.available2022-03-28T10:28:09Z
dc.identifier.issn1526-1492
dc.identifier.urihttps://reunir.unir.net/handle/123456789/12734
dc.description.abstractSecurity weaknesses in web applications deployed in cloud architectures can seriously affect its data confidentiality and integrity. The construction of the procedure utilized in the static analysis tools of source code security differs and therefore each tool finds a different number of each weakness type for which it is designed. To utilize the possible synergies different static analysis tools may process, this work uses a new method to combine several source codes aiming to investigate how to increase the performance of security weakness detection while reducing the number of false positives. Specifically, five static analysis tools will be combined with the designed method to study their behavior using an updated benchmark for OWASP Top Ten Security Weaknesses (OWASP TTSW). The method selects specific metrics to rank the tools for different criticality levels of web applications considering different weights in the ratios. The findings show that simply including more tools in a combination is not synonymous with better results; it depends on the specific tools included in the combination due to their different designs and techniques.es_ES
dc.language.isoenges_ES
dc.publisherTech Science Presses_ES
dc.relation.ispartofseries;vol. 129, nº 2
dc.relation.urihttps://www.techscience.com/CMES/v129n2/44808es_ES
dc.rightsopenAccesses_ES
dc.subjectbenchmarkes_ES
dc.subjectcomparative methodologyes_ES
dc.subjectsecurity testing analysises_ES
dc.subjecttools combinationes_ES
dc.subjectweaknesses_ES
dc.subjectweb applicationes_ES
dc.subjectScopuses_ES
dc.subjectJCRes_ES
dc.titleCombinatorial method with static analysis for source code security in web applicationses_ES
dc.typearticlees_ES
reunir.tag~ARIes_ES
dc.identifier.doihttps://doi.org/10.32604/cmes.2021.017213


Ficheros en el ítem

FicherosTamañoFormatoVer

No hay ficheros asociados a este ítem.

Este ítem aparece en la(s) siguiente(s) colección(ones)

Mostrar el registro sencillo del ítem