• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Enhancing Software Security Analysis: Targeted Test Case Generation through Constraint Solving in Interactive Application Security Testing
 
  • Details
  • Full
Options
October 29, 2024
Conference Paper
Title

Enhancing Software Security Analysis: Targeted Test Case Generation through Constraint Solving in Interactive Application Security Testing

Abstract
Interactive Application Security Testing (IAST) is an innovative approach to improving software security assessment by combining the strengths of static and dynamic analysis, offering a more comprehensive and accurate assessment. This hybrid approach enables the identification of true positives resulting from static analysis, via confirmation through dynamic analysis. This paper presents techniques for generating specific test cases to verify static analysis findings by employing constraint-solving. Given the necessity for enhanced efficiency and accuracy in vulnerability identification in resource-constrained environments, such as embedded systems, where memory management issues are a significant vulnerability, our solution will concentrate on C code applications. Accordingly, one particular challenge that will be addressed is how to deal with pointers and memory management during the constraints collection. Furthermore, we will introduce methods that are used to handle external function calls - which pose a particular challenge because their source code is usually not available - and to cope with the state explosion problem through the early detection of paths that do not require further exploration.
Author(s)
Barakat, Ramon  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Weiß, Paul
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Schneider, Martin A.
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Kraus, Roman  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Blanckenburg, Jasper von
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Mainwork
IEEE 24th International Conference on Software Quality, Reliability, and Security Companion, QRS-C 2024. Proceedings  
Conference
International Conference on Software Quality, Reliability and Security Companion 2024  
DOI
10.1109/QRS-C63300.2024.00018
Language
English
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Keyword(s)
  • Accuracy

  • Source coding

  • Memory management

  • Static analysis

  • Software quality

  • Application security

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024