Jingyun Zhu

dblp:376/0144 · DBLP profile ↗
← Back
1ranked-venue papers
1as first author
1since 2021 · last 2024
0009-0000-5919-6552ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 77% Web and mobile security · 23%
Software engineering, system software, and programming languages
1 paper
Software testing · 50% Program analysis · 50%

Topics — the 6 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › vulnerability discovery › static analysis
static vulnerability detection
0.812024
A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android · IEEE Trans. Software Eng. 2024
Systems and software security
vulnerability discovery
0.812024
A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android · IEEE Trans. Software Eng. 2024
Software testing
software testing tools
0.812024
A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android · IEEE Trans. Software Eng. 2024
Program analysis › static analysis
static analysis tools
0.812024
A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android · IEEE Trans. Software Eng. 2024
Web and mobile security › mobile security
android security
0.212024
A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android · IEEE Trans. Software Eng. 2024
Web and mobile security
mobile security
0.212024
A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android · IEEE Trans. Software Eng. 2024

Methods — techniques the papers use, named apart from their topics

empirical study · 1.5benchmarking · 1.5
YearPublicationVenuePosition
2024 A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android
abstract
To identify security vulnerabilities in Android applications, numerous static application security testing (SAST) tools have been proposed. However, it poses significant challenges to assess their overall performance on diverse vulnerability types. The task is non-trivial and poses considerable challenges. Firstly, the absence of a unified evaluation platform for defining and describing tools’ supported vulnerability types, coupled with the lack of normalization for the intricate and varied reports generated by different tools, significantly adds to the complexity. Secondly, there is a scarcity of adequate benchmarks, particularly those derived from real-world scenarios. To address these problems, we are the first to propose a unified platform namedVulsTotal, supporting various vulnerability types, enabling comprehensive and versatile analysis across diverse SAST tools. Specifically, we begin by meticulously selecting 11 free and open-sourced SAST tools from a pool of 97 existing options, adhering to clearly defined criteria. After that, we invest significant efforts in comprehending the detection rules of each tool, subsequently unifying 67 general/common vulnerability types for Android SAST tools. We also redefine and implement a standardized reporting format, ensuring uniformity in presenting results across all tools. Additionally, to mitigate the problem of benchmarks, we conducted a manual analysis of huge amounts of CVEs to construct a new CVE-based benchmark based on our comprehension of Android app vulnerabilities. Leveraging the evaluation platform, which integrates both existing synthetic benchmarks and newly constructed CVE-based benchmarks from this study, we conducted a comprehensive analysis to evaluate and compare these selected tools from various perspectives, such as general vulnerability type coverage, type consistency, tool effectiveness, and time performance. Our observations yielded impressive findings, like the technical reasons underlying the performance, which provide insights for different stakeholders.
Jingyun Zhu, Kaixuan Li 0002, Sen Chen 0001, Lingling Fan 0003, Junjie Wang 0007, Xiaofei Xie
IEEE Trans. Software Eng.1