Please use this identifier to cite or link to this item:
http://bura.brunel.ac.uk/handle/2438/30373
Title: | Do Developers Use Static Application Security Testing (SAST) Tools Straight Out of the Box? A large-scale Empirical Study |
Authors: | Bennett, G |
Keywords: | static analysis;survey;vulnerability detection |
Issue Date: | 24-Oct-2024 |
Publisher: | Association for Computing Machinery (ACM) |
Citation: | Bennett, G. et al. (2024) 'Do Developers Use Static Application Security Testing (SAST) Tools Straight Out of the Box? A large-scale Empirical Study', ESEM '24: Proceedings of the 18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement, Barcelona, Spain, 24-25 October, pp.454 - 460. doi: 10.1145/3674805. |
Abstract: | Static application Security Testing (SAST) tools are an established means of detecting vulnerabilities early in development. Previous studies have reported low detection rates from SAST tools and recommend either combining SAST tools or configuring rule sets to detect more vulnerabilities. However, while previous work suggests that developers rarely combine or configure any of the Automatic Static Analysis Tools (ASATs) they use, it is currently unclear whether SAST tools are used directly “out of the box”. To understand how developers use SAST tools, we performed a large-scale survey involving 1,263 developers. We pre-screened developers to establish their SAST use and found that only 20% (204/1,003) used SAST tools. Of those developers who did use SAST tools, we found a large number did not use multiple tools (59%), did not configure tools (54%) or did neither (40%). Our results suggest that more work is needed to help developers combine and configure tools, since doing so is likely to detect significantly more vulnerabilities. |
URI: | https://bura.brunel.ac.uk/handle/2438/30373 |
DOI: | https://doi.org/10.1145/3674805 |
ISBN: | 9798400710476 |
Other Identifiers: | ORCiD: Tracy Hall https://orcid.org/0000-0002-2728-9014 ORCiD: Steve Counsell https://orcid.org/0000-0002-2939-8919 ORCiD: Thomas Shippey https://orcid.org/0000-0003-1890-3390 |
Appears in Collections: | Dept of Computer Science Research Papers |
Files in This Item:
File | Description | Size | Format | |
---|---|---|---|---|
FullText.pdf | Copyright © 2024 Owner/Author. This work is licensed under a Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). | 469.75 kB | Adobe PDF | View/Open |
This item is licensed under a Creative Commons License