Skip to content

OWASP Benchmark is a test suite designed to verify the speed and accuracy of software vulnerability detection tools. A fully runnable web app written in Java, it supports analysis by Static (SAST), Dynamic (DAST), and Runtime (IAST) tools that support Java. The idea is that since it is fully runnable and all the vulnerabilities are actually exploit

License

Notifications You must be signed in to change notification settings

testable-eu/BenchmarkJava

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

OWASP Benchmark with TESTABLE Enhancements

This is a fork of the OWASP Benchmark project, which aims to discover testability patterns in web application code which make it hard for dynamic testing tools to detect vulnerabilities.

Running

Here are some steps to build and run the benchmark.

Building and Benchmarking

Everything is run within docker containers:

cd VMs
docker compose up --build

This will build and start the benchmark, including testing using OWASP ZAP.

Create Scorecards

To create scorecards, copy the results where benchmark can find them:

cp VMs/zap/wrk/results/2023-09-21-ZAP-Report-benchmark.xml results/

Then run the scorecard script:

bash createScorecards.sh

You will find the results in the scorecard directory.

Evaluate patterns

Currently just a simple python script that looks for strings and tries to correlate them to false negatives:

python3 scripts/simplePattern.py

ZAP

To configure ZAP, here are some useful links:

OWASP Benchmark

The OWASP Benchmark Project is a Java test suite designed to verify the speed and accuracy of vulnerability detection tools. It is a fully runnable open source web application that can be analyzed by any type of Application Security Testing (AST) tool, including SAST, DAST (like OWASP ZAP), and IAST tools. The intent is that all the vulnerabilities deliberately included in and scored by the Benchmark are actually exploitable so its a fair test for any kind of application vulnerability detection tool. The Benchmark also includes scorecard generators for numerous open source and commercial AST tools, and the set of supported tools is growing all the time.

The project documentation is all on the OWASP site at the OWASP Benchmark project pages. Please refer to that site for all the project details.

The current latest release is v1.2. Note that all the releases that are available here: https://github.com/OWASP/Benchmark/releases are historical. The latest release is always available live by simply cloning or pulling the head of this repository (i.e., git pull).

About

OWASP Benchmark is a test suite designed to verify the speed and accuracy of software vulnerability detection tools. A fully runnable web app written in Java, it supports analysis by Static (SAST), Dynamic (DAST), and Runtime (IAST) tools that support Java. The idea is that since it is fully runnable and all the vulnerabilities are actually exploit

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Java 68.0%
  • HTML 25.3%
  • Jupyter Notebook 6.5%
  • Shell 0.1%
  • JavaScript 0.1%
  • Batchfile 0.0%