Evaluating the Use of Open-Source and Standalone SAST Tools for Detecting Vulnerabilities in C/C++ Projects
Valdeclébio Farrapo, Emanuel Rodrigues, José Maria Monteiro, Javam Machado
2025
Abstract
Detecting security vulnerabilities in the source code of software systems is one of the most significant challenges in the field of information security. In this context, the Open Web Application Security Project (OWASP) defines Static Application Security Testing (SAST) tools as those capable of statically analyzing the source code, without executing it, to identify security vulnerabilities, bugs, and code smells during the coding phase, when it is relatively inexpensive to detect and resolve security issues. However, most wellknown SAST tools are commercial and web-based, requiring the upload of the source code to a “trusted” remote server. In this paper, our goal is to investigate the viability of using open-source standalone SAST tools for detecting security vulnerabilities in C/C++ projects. To achieve our goal, we conduct an empirical study in which we examine 30 large and popular C/C++ projects using two different state-of-the-art opensource and standalone SAST tools. The results demonstrate the potential of using open-source standalone SAST tools as a means to evaluate the security risks of a software product without manually reviewing all the warnings.
DownloadPaper Citation
in Harvard Style
Farrapo V., Rodrigues E., Monteiro J. and Machado J. (2025). Evaluating the Use of Open-Source and Standalone SAST Tools for Detecting Vulnerabilities in C/C++ Projects. In Proceedings of the 27th International Conference on Enterprise Information Systems - Volume 1: ICEIS; ISBN 978-989-758-749-8, SciTePress, pages 394-401. DOI: 10.5220/0013483500003929
in Bibtex Style
@conference{iceis25,
author={Valdeclébio Farrapo and Emanuel Rodrigues and José Monteiro and Javam Machado},
title={Evaluating the Use of Open-Source and Standalone SAST Tools for Detecting Vulnerabilities in C/C++ Projects},
booktitle={Proceedings of the 27th International Conference on Enterprise Information Systems - Volume 1: ICEIS},
year={2025},
pages={394-401},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0013483500003929},
isbn={978-989-758-749-8},
}
in EndNote Style
TY - CONF
JO - Proceedings of the 27th International Conference on Enterprise Information Systems - Volume 1: ICEIS
TI - Evaluating the Use of Open-Source and Standalone SAST Tools for Detecting Vulnerabilities in C/C++ Projects
SN - 978-989-758-749-8
AU - Farrapo V.
AU - Rodrigues E.
AU - Monteiro J.
AU - Machado J.
PY - 2025
SP - 394
EP - 401
DO - 10.5220/0013483500003929
PB - SciTePress