Many Tools, Few Exploitable Vulnerabilities: A Survey of 246 Static Code Analyzers for Security
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Hermann, Kevin, Peldszus, Sven, Berger, Thorsten |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2026
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
Can I Check What I Designed? Mapping Security Design DSLs to Code Analyzers
von: Peldszus, Sven, et al.
Veröffentlicht: (2026)
von: Peldszus, Sven, et al.
Veröffentlicht: (2026)
An Exploratory Study on the Engineering of Security Features
von: Hermann, Kevin, et al.
Veröffentlicht: (2025)
von: Hermann, Kevin, et al.
Veröffentlicht: (2025)
120 Domain-Specific Languages for Security
von: Krausz, Markus, et al.
Veröffentlicht: (2024)
von: Krausz, Markus, et al.
Veröffentlicht: (2024)
A Taxonomy of Functional Security Features and How They Can Be Located
von: Hermann, Kevin, et al.
Veröffentlicht: (2025)
von: Hermann, Kevin, et al.
Veröffentlicht: (2025)
Triggering and Detecting Exploitable Library Vulnerability from the Client by Directed Greybox Fuzzing
von: Zhao, Yukai, et al.
Veröffentlicht: (2026)
von: Zhao, Yukai, et al.
Veröffentlicht: (2026)
Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker Contracts
von: Yang, Shuo, et al.
Veröffentlicht: (2024)
von: Yang, Shuo, et al.
Veröffentlicht: (2024)
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
von: Marquer, Yoann, et al.
Veröffentlicht: (2026)
von: Marquer, Yoann, et al.
Veröffentlicht: (2026)
A Comprehensive Study of Exploitable Patterns in Smart Contracts: From Vulnerability to Defense
von: Ding, Yuchen, et al.
Veröffentlicht: (2025)
von: Ding, Yuchen, et al.
Veröffentlicht: (2025)
Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
von: Huang, Charoes, et al.
Veröffentlicht: (2026)
von: Huang, Charoes, et al.
Veröffentlicht: (2026)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
von: Cusick, James J.
Veröffentlicht: (2025)
von: Cusick, James J.
Veröffentlicht: (2025)
QLCoder: A Query Synthesizer For Static Analysis of Security Vulnerabilities
von: Wang, Claire, et al.
Veröffentlicht: (2025)
von: Wang, Claire, et al.
Veröffentlicht: (2025)
Assessing Vulnerability in Smart Contracts: The Role of Code Complexity Metrics in Security Analysis
von: Tehrani, Masoud Jamshidiyan
Veröffentlicht: (2024)
von: Tehrani, Masoud Jamshidiyan
Veröffentlicht: (2024)
IRIS: LLM-Assisted Static Analysis for Detecting Security Vulnerabilities
von: Li, Ziyang, et al.
Veröffentlicht: (2024)
von: Li, Ziyang, et al.
Veröffentlicht: (2024)
Expert-in-the-Loop Systems with Cross-Domain and In-Domain Few-Shot Learning for Software Vulnerability Detection
von: Farr, David, et al.
Veröffentlicht: (2025)
von: Farr, David, et al.
Veröffentlicht: (2025)
Guiding Symbolic Execution with Static Analysis and LLMs for Vulnerability Discovery
von: Shafiuzzaman, Md, et al.
Veröffentlicht: (2026)
von: Shafiuzzaman, Md, et al.
Veröffentlicht: (2026)
UEFI Vulnerability Signature Generation using Static and Symbolic Analysis
von: Shafiuzzaman, Md, et al.
Veröffentlicht: (2024)
von: Shafiuzzaman, Md, et al.
Veröffentlicht: (2024)
An Extensive Comparison of Static Application Security Testing Tools
von: Esposito, Matteo, et al.
Veröffentlicht: (2024)
von: Esposito, Matteo, et al.
Veröffentlicht: (2024)
DITING: A Static Analyzer for Identifying Bad Partitioning Issues in TEE Applications
von: Ma, Chengyan, et al.
Veröffentlicht: (2025)
von: Ma, Chengyan, et al.
Veröffentlicht: (2025)
CrossInspector: A Static Analysis Approach for Cross-Contract Vulnerability Detection
von: Chen, Xiao
Veröffentlicht: (2024)
von: Chen, Xiao
Veröffentlicht: (2024)
QLPro: Automated Code Vulnerability Discovery via LLM and Static Code Analysis Integration
von: Hu, Junze, et al.
Veröffentlicht: (2025)
von: Hu, Junze, et al.
Veröffentlicht: (2025)
"False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
von: Ami, Amit Seal, et al.
Veröffentlicht: (2023)
von: Ami, Amit Seal, et al.
Veröffentlicht: (2023)
An Empirical Study on the Security Vulnerabilities of GPTs
von: Wu, Tong, et al.
Veröffentlicht: (2025)
von: Wu, Tong, et al.
Veröffentlicht: (2025)
Security study based on the Chatgptplugin system: ldentifying Security Vulnerabilities
von: Ren, Ruomai
Veröffentlicht: (2025)
von: Ren, Ruomai
Veröffentlicht: (2025)
CASTLE: Benchmarking Dataset for Static Code Analyzers and LLMs towards CWE Detection
von: Dubniczky, Richard A., et al.
Veröffentlicht: (2025)
von: Dubniczky, Richard A., et al.
Veröffentlicht: (2025)
Fixing Security Vulnerabilities with AI in OSS-Fuzz
von: Zhang, Yuntong, et al.
Veröffentlicht: (2024)
von: Zhang, Yuntong, et al.
Veröffentlicht: (2024)
SecureFixAgent: A Hybrid LLM Agent for Automated Python Static Vulnerability Repair
von: Gajjar, Jugal, et al.
Veröffentlicht: (2025)
von: Gajjar, Jugal, et al.
Veröffentlicht: (2025)
WACANA: A Concolic Analyzer for Detecting On-chain Data Vulnerabilities in WASM Smart Contracts
von: Wang, Wansen, et al.
Veröffentlicht: (2024)
von: Wang, Wansen, et al.
Veröffentlicht: (2024)
LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
von: Xiang, Jiahui, et al.
Veröffentlicht: (2024)
von: Xiang, Jiahui, et al.
Veröffentlicht: (2024)
R+R: Security Vulnerability Dataset Quality Is Critical
von: Yadav, Anurag Swarnim, et al.
Veröffentlicht: (2025)
von: Yadav, Anurag Swarnim, et al.
Veröffentlicht: (2025)
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
von: Cheng, Yiran, et al.
Veröffentlicht: (2024)
von: Cheng, Yiran, et al.
Veröffentlicht: (2024)
Deep Learning Aided Software Vulnerability Detection: A Survey
von: Uddin, Md Nizam, et al.
Veröffentlicht: (2025)
von: Uddin, Md Nizam, et al.
Veröffentlicht: (2025)
Unsupervised Binary Code Translation with Application to Code Similarity Detection and Vulnerability Discovery
von: Ahmad, Iftakhar, et al.
Veröffentlicht: (2024)
von: Ahmad, Iftakhar, et al.
Veröffentlicht: (2024)
LLM-based Vulnerability Discovery through the Lens of Code Metrics
von: Weissberg, Felix, et al.
Veröffentlicht: (2025)
von: Weissberg, Felix, et al.
Veröffentlicht: (2025)
Where Do Smart Contract Security Analyzers Fall Short?
von: Abdelaziz, Tamer, et al.
Veröffentlicht: (2026)
von: Abdelaziz, Tamer, et al.
Veröffentlicht: (2026)
AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts
von: Basak, Setu Kumar, et al.
Veröffentlicht: (2024)
von: Basak, Setu Kumar, et al.
Veröffentlicht: (2024)
CrossCommitVuln-Bench: A Dataset of Multi-Commit Python Vulnerabilities Invisible to Per-Commit Static Analysis
von: Majumdar, Arunabh
Veröffentlicht: (2026)
von: Majumdar, Arunabh
Veröffentlicht: (2026)
Impact of Code Transformation on Detection of Smart Contract Vulnerabilities
von: Manh, Cuong Tran, et al.
Veröffentlicht: (2024)
von: Manh, Cuong Tran, et al.
Veröffentlicht: (2024)
A Slicing-Based Approach for Detecting and Patching Vulnerable Code Clones
von: Alomari, Hakam, et al.
Veröffentlicht: (2025)
von: Alomari, Hakam, et al.
Veröffentlicht: (2025)
SecCodePRM: A Process Reward Model for Code Security
von: Yu, Weichen, et al.
Veröffentlicht: (2026)
von: Yu, Weichen, et al.
Veröffentlicht: (2026)
LLM Security Guard for Code
von: Kavian, Arya, et al.
Veröffentlicht: (2024)
von: Kavian, Arya, et al.
Veröffentlicht: (2024)
Ähnliche Einträge
-
Can I Check What I Designed? Mapping Security Design DSLs to Code Analyzers
von: Peldszus, Sven, et al.
Veröffentlicht: (2026) -
An Exploratory Study on the Engineering of Security Features
von: Hermann, Kevin, et al.
Veröffentlicht: (2025) -
120 Domain-Specific Languages for Security
von: Krausz, Markus, et al.
Veröffentlicht: (2024) -
A Taxonomy of Functional Security Features and How They Can Be Located
von: Hermann, Kevin, et al.
Veröffentlicht: (2025) -
Triggering and Detecting Exploitable Library Vulnerability from the Client by Directed Greybox Fuzzing
von: Zhao, Yukai, et al.
Veröffentlicht: (2026)