In Software Development Life Cycle (SDLC), security vulnerabilities are one of the points introduced during the construction stage. Failure to detect software defects earlier after releasing the product to the market causes higher repair costs for the company. So, it decreases the company's reputation, violates user privacy, and causes an unrepairable issue for the application. The introduction of vulnerability detection enables reducing the number of false alerts to focus the limited testing efforts on potentially vulnerable files. UMKM Masa Kini (UMI) is a Point of Sales application to sell any Micro, Small, and Medium Enterprises Product (UMKM). Therefore, in the current work, we analyze the suitability of these metrics to create Machine Learning based software vulnerability detectors for UMI applications. Code is generated using a commercial tool, SonarCloud. Experimental result shows that there are 3,285 vulnerable rules detected.
翻译:在软件开发生命周期(SDLC)中,安全漏洞是在构建阶段引入的关键问题之一。产品发布到市场后未能提前检测出软件缺陷,会导致企业修复成本增加,进而损害公司声誉、侵犯用户隐私,并为应用程序带来不可修复的后果。引入漏洞检测技术能够减少误报数量,从而将有限的测试资源集中用于可能存在漏洞的文件。UMKM Masa Kini(UMI)是一款面向中小微企业产品销售的零售终端应用。因此,本研究分析了使用这些指标构建基于机器学习软件漏洞检测器对UMI应用的适用性。代码通过商业工具SonarCloud生成,实验结果显示共检测到3,285条漏洞规则。