Is the OWASP Top 10 list comprehensive enough for writing secure code?

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
1. Verfasser: Sane, Parth
Format: Preprint
Veröffentlicht: 2020
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866914675039404032
author Sane, Parth
author_facet Sane, Parth
contents The OWASP Top 10 is a list that is published by the Open Web Application Security Project (OWASP). The general purpose is to serve as a watchlist for bugs to avoid while writing code. This paper compares how many of those weakness as described in the top ten list are actually reported in vulnerabilities listed in the National Vulnerability Database (NVD). That way it makes it possible to empirically show whether the OWASP Top 10 list is comprehensive enough or not, for code weaknesses that have been found in the past decade.
format Preprint
id arxiv_https___arxiv_org_abs_2002_11269
institution arXiv
publishDate 2020
record_format arxiv
spellingShingle Is the OWASP Top 10 list comprehensive enough for writing secure code?
Sane, Parth
Cryptography and Security
Networking and Internet Architecture
Software Engineering
The OWASP Top 10 is a list that is published by the Open Web Application Security Project (OWASP). The general purpose is to serve as a watchlist for bugs to avoid while writing code. This paper compares how many of those weakness as described in the top ten list are actually reported in vulnerabilities listed in the National Vulnerability Database (NVD). That way it makes it possible to empirically show whether the OWASP Top 10 list is comprehensive enough or not, for code weaknesses that have been found in the past decade.
title Is the OWASP Top 10 list comprehensive enough for writing secure code?
topic Cryptography and Security
Networking and Internet Architecture
Software Engineering
url https://arxiv.org/abs/2002.11269