• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. VUSC: An Extensible Research Platform for Java-Based Static Analysis
 
  • Details
  • Full
Options
November 16, 2025
Conference Paper
Title

VUSC: An Extensible Research Platform for Java-Based Static Analysis

Abstract
Detecting security vulnerabilities in backend Web applications as well as mobile apps is extremely important. Static analysis for vulnerability analysis has subsequently developed as an important field of research. Researchers need extensible frameworks to avoid starting from scratch with every new research project. Compared to commercially available scanners, open-source frameworks often only provide basic functionality. This limits the ability of researchers to evaluate novel algorithms. Lacking access to full code scanners, new building blocks are often tested in isolation. In this paper, we present VUSC, a fast, precise and extensible vulnerability scanner for Android and Java bytecode. It features a plugin architecture for commonly used static analyses such as call graph, taint and value analyses, allowing researchers to build upon our work and using VUSC as a reference platform. We show that VUSC achieves a precision of around 90% on benchmarks. Video: https://youtu.be/QpXs9hv5zGc, Dataset: https://github.com/Fraunhofer-SIT/ASE2025-StaticAnalysisInfrastructure/
Author(s)
Miltenberger, Marc  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Arzt, Steven  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Mainwork
40th IEEE/ACM International Conference on Automated Software Engineering, ASE 2025. Proceedings  
Conference
International Conference on Automated Software Engineering 2025  
DOI
10.1109/ASE63991.2025.00354
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024