A Comprehensive Study on Quality Assurance Tools for Java
Han Liu, Sen Chen, Ruitao Feng, Chengwei Liu, Kaixuan Li, Zhengzi Xu, Liming Nie, Yang Liu, Yixiang Chen
摘要
Quality assurance (QA) tools are receiving more and more attention and are widely used by developers. Given the wide range of solutions for QA technology, it is still a question of evaluating QA tools. Most existing research is limited in the following ways: (i) They compare tools without considering scanning rules analysis. (ii) They disagree on the effectiveness of tools due to the study methodology and benchmark dataset. (iii) They do not separately analyze the role of the warnings. (iv) There is no large-scale study on the analysis of time performance. To address these problems, in the paper, we systematically select 6 free or open-source tools for a comprehensive study from a list of 148 existing Java QA tools. To carry out a comprehensive study and evaluate tools in multi-level dimensions, we first mapped the scanning rules to the CWE and analyze the coverage and granularity of the scanning rules. Then we conducted an experiment on 5 benchmarks, including 1,425 bugs, to investigate the effectiveness of these tools. Furthermore, we took substantial effort to investigate the effectiveness of warnings by comparing the real labeled bugs with the warnings and investigating their role in bug detection. Finally, we assessed these tools’ time performance on 1,049 projects. The useful findings based on our comprehensive study can help developers improve their tools and provide users with suggestions for selecting QA tools.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Comparison and Evaluation on Static Application Security Testing (SAST) Tools for JavaKaixuan Li, Sen Chen, Lingling Fan, Ruitao Feng 等FSE 2023 · 被引用 43 次
- Learning to Locate and Describe VulnerabilitiesJian Zhang, Shangqing Liu, Xu Wang, Tianlin Li 等ASE 2023 · 被引用 8 次
- Understanding and Detecting Annotation-Induced Faults of Static AnalyzersHuaien Zhang, Yu Pei, Shuyun Liang, Shin Hwei TanFSE 2024 · 被引用 4 次
- Anota: Identifying Business Logic Vulnerabilities via Annotation-Based SanitizationMeng Wang, Philipp Görz, Joschua Schilling, Keno Hassler 等NDSS 2026 · 被引用 4 次
- Understanding Industry Perspectives of Static Application Security Testing (SAST) EvaluationYuan Li, Peisen Yao, Kan Yu, Chengpeng Wang 等FSE 2025 · 被引用 1 次
它引用的顶会 Paper7
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 被引用 373 次
- How effective are smart contract analysis tools? evaluating smart contract static analysis tools using bug injectionAsem Ghaleb, Karthik PattabiramanISSTA 2020 · 被引用 183 次
- An empirical study on the effectiveness of static C code analyzers for vulnerability detectionStephan Lipp, Sebastian Banescu, Alexander PretschnerISSTA 2022 · 被引用 99 次
- An empirical assessment of security risks of global Android banking appsSen Chen, Lingling Fan, Guozhu Meng, Ting Su 等ICSE 2020 · 被引用 70 次
- A large-scale study of usability criteria addressed by static analysis toolsMarcus Nachtigall, Michael Schlichtig, Eric BoddenISSTA 2022 · 被引用 38 次
相关 Paper
- Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java ProjectsLida Zhao, Sen Chen, Zhengzi Xu, Chengwei Liu 等FSE 2023 · 被引用 42 次
- On the Real-World Effectiveness of Static Bug Detectors at Finding Null Pointer ExceptionsDavid A. Tomassi, Cindy Rubio-GonzálezASE 2021 · 被引用 24 次
- On the Relationship between Code Verifiability and UnderstandabilityKobi Feldman, Martin Kellogg, Oscar ChaparroFSE 2023 · 被引用 2 次
- Detecting Metadata-Related Bugs in Enterprise ApplicationsMd Mahir Asef Kabir, Xiaoyin Wang, Na MengFSE 2025 · 被引用 1 次
- Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java ProjectsStefan Schott, Serena Elisa Ponta, Wolfram Fischer, Jonas Klauke 等ICSE 2026
