ant-application-security-testing-benchmark icon indicating copy to clipboard operation
ant-application-security-testing-benchmark copied to clipboard

xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".

Results 9 ant-application-security-testing-benchmark issues
Sort by recently updated
recently updated
newest added

增加引擎评价体系文档指引

update sast-java evaluation items & cases 修改了部分评价项,自查后补充了部分测试用例

二阶段计划: - 准确度 - 对象敏感 - 别名是否被污染 - 上下文敏感 - AST节点枚举传播场景 - 表达式 - 污点对象的完整度 - java原生对象 - 数组 详细: - accuracy - contextSensitive - DifferentParamsForFunction_001_T.java - DifferentParamsForFunction_002_F.java - DifferentParamsForFunction_003_T.java...

三阶段计划: - 准确度 - 对象敏感 - 别名是否被污染 - BaseAlias - FieldAlias - HeapContextAlias - HeapOverwriteAlias - HeapPointsToSelfAlias - InnerClassAlias - MultiFieldAccessAlias - 上下文敏感 - 相同函数调用不同参数 - HeapAllocSite - MultipleCallSite -...