Matches in SemOpenAlex for { <https://semopenalex.org/work/W2770623724> ?p ?o ?g. }
- W2770623724 abstract "The incorrect use of cryptography is a common source of critical software vulnerabilities. As developers lack knowledge in applied cryptography and support from experts is scarce, this situation is frequently addressed by adopting static code analysis tools to automatically detect cryptography misuse during coding and reviews, even if the effectiveness of such tools is far from being well understood. This paper proposes a method for benchmarking static code analysis tools for the detection of cryptography misuse, and evaluates the method in a case study, with the goal of selecting the most adequate tools for specific development contexts. Our method classifies cryptography misuse in nine categories recognized by developers (weak cryptography, poor key management, bad randomness, etc.) and provides the workload, metrics and procedure needed for a fair assessment and comparison of tools. We found that all evaluated tools together detected only 35% of cryptography misuses in our tests. Furthermore, none of the evaluated tools detected insecure elliptic curves, weak parameters in key agreement, and most insecure configurations for RSA and ECDSA. This suggests cryptography misuse is underestimated by tool builders. Despite that, we show that it is possible to benefit from an adequate tool selection during the development of cryptographic software." @default.
- W2770623724 created "2017-12-04" @default.
- W2770623724 creator A5016622594 @default.
- W2770623724 creator A5029184440 @default.
- W2770623724 creator A5030619096 @default.
- W2770623724 creator A5063901162 @default.
- W2770623724 creator A5077598713 @default.
- W2770623724 date "2017-10-01" @default.
- W2770623724 modified "2023-09-30" @default.
- W2770623724 title "Practical Evaluation of Static Analysis Tools for Cryptography: Benchmarking Method and Case Study" @default.
- W2770623724 cites W108218230 @default.
- W2770623724 cites W1517949462 @default.
- W2770623724 cites W1558012247 @default.
- W2770623724 cites W1761184020 @default.
- W2770623724 cites W1985424295 @default.
- W2770623724 cites W2008810193 @default.
- W2770623724 cites W2020841721 @default.
- W2770623724 cites W2025411198 @default.
- W2770623724 cites W2042923641 @default.
- W2770623724 cites W2076239188 @default.
- W2770623724 cites W2078142664 @default.
- W2770623724 cites W2084864601 @default.
- W2770623724 cites W2085032701 @default.
- W2770623724 cites W2092115639 @default.
- W2770623724 cites W2093791094 @default.
- W2770623724 cites W2103370348 @default.
- W2770623724 cites W2129426180 @default.
- W2770623724 cites W2145994642 @default.
- W2770623724 cites W2209872464 @default.
- W2770623724 cites W2269664735 @default.
- W2770623724 cites W2279161046 @default.
- W2770623724 cites W2280486853 @default.
- W2770623724 cites W2290790037 @default.
- W2770623724 cites W2357927175 @default.
- W2770623724 cites W2401113443 @default.
- W2770623724 cites W2521898510 @default.
- W2770623724 cites W2590214825 @default.
- W2770623724 cites W4250848060 @default.
- W2770623724 cites W4290474734 @default.
- W2770623724 cites W4291213652 @default.
- W2770623724 doi "https://doi.org/10.1109/issre.2017.27" @default.
- W2770623724 hasPublicationYear "2017" @default.
- W2770623724 type Work @default.
- W2770623724 sameAs 2770623724 @default.
- W2770623724 citedByCount "6" @default.
- W2770623724 countsByYear W27706237242018 @default.
- W2770623724 countsByYear W27706237242020 @default.
- W2770623724 countsByYear W27706237242021 @default.
- W2770623724 countsByYear W27706237242022 @default.
- W2770623724 countsByYear W27706237242023 @default.
- W2770623724 crossrefType "proceedings-article" @default.
- W2770623724 hasAuthorship W2770623724A5016622594 @default.
- W2770623724 hasAuthorship W2770623724A5029184440 @default.
- W2770623724 hasAuthorship W2770623724A5030619096 @default.
- W2770623724 hasAuthorship W2770623724A5063901162 @default.
- W2770623724 hasAuthorship W2770623724A5077598713 @default.
- W2770623724 hasConcept C144133560 @default.
- W2770623724 hasConcept C148730421 @default.
- W2770623724 hasConcept C162853370 @default.
- W2770623724 hasConcept C167615521 @default.
- W2770623724 hasConcept C178489894 @default.
- W2770623724 hasConcept C203062551 @default.
- W2770623724 hasConcept C22680326 @default.
- W2770623724 hasConcept C26517878 @default.
- W2770623724 hasConcept C29983905 @default.
- W2770623724 hasConcept C38652104 @default.
- W2770623724 hasConcept C41008148 @default.
- W2770623724 hasConcept C527648132 @default.
- W2770623724 hasConcept C62913178 @default.
- W2770623724 hasConcept C86251818 @default.
- W2770623724 hasConceptScore W2770623724C144133560 @default.
- W2770623724 hasConceptScore W2770623724C148730421 @default.
- W2770623724 hasConceptScore W2770623724C162853370 @default.
- W2770623724 hasConceptScore W2770623724C167615521 @default.
- W2770623724 hasConceptScore W2770623724C178489894 @default.
- W2770623724 hasConceptScore W2770623724C203062551 @default.
- W2770623724 hasConceptScore W2770623724C22680326 @default.
- W2770623724 hasConceptScore W2770623724C26517878 @default.
- W2770623724 hasConceptScore W2770623724C29983905 @default.
- W2770623724 hasConceptScore W2770623724C38652104 @default.
- W2770623724 hasConceptScore W2770623724C41008148 @default.
- W2770623724 hasConceptScore W2770623724C527648132 @default.
- W2770623724 hasConceptScore W2770623724C62913178 @default.
- W2770623724 hasConceptScore W2770623724C86251818 @default.
- W2770623724 hasLocation W27706237241 @default.
- W2770623724 hasOpenAccess W2770623724 @default.
- W2770623724 hasPrimaryLocation W27706237241 @default.
- W2770623724 hasRelatedWork W1848359393 @default.
- W2770623724 hasRelatedWork W2127025027 @default.
- W2770623724 hasRelatedWork W2155350564 @default.
- W2770623724 hasRelatedWork W2329452785 @default.
- W2770623724 hasRelatedWork W2356380379 @default.
- W2770623724 hasRelatedWork W2363925233 @default.
- W2770623724 hasRelatedWork W2366284060 @default.
- W2770623724 hasRelatedWork W3009603553 @default.
- W2770623724 hasRelatedWork W3211894641 @default.
- W2770623724 hasRelatedWork W4307929433 @default.
- W2770623724 isParatext "false" @default.
- W2770623724 isRetracted "false" @default.
- W2770623724 magId "2770623724" @default.