empty
empty

OWASP Benchmark Scorecard for FBwFindSecBugs v1.5.0 (SAST)

The OWASP Benchmark is a test suite designed to evaluate the speed, coverage, and accuracy of automated vulnerability detection tools. Without the ability to measure these tools, it is difficult to understand their strengths and weaknesses, and compare them to each other. The Benchmark contains thousands of test cases that are fully runnable and exploitable. The following is the scorecard for the tool FBwFindSecBugs against version 1.2beta of the Benchmark. It shows how well this tool finds true positives and avoids false positives in the Benchmark test cases.

For more information, please visit the OWASP Benchmark Project Site.

Statistics

Tool elapsed analysis time 0:01:19
Tool overall score (0-100) 39,10%
Total test cases 2740
Download raw results Actual Results

Detailed Results

CategoryCWE #TPFNTNFPTotalTPRFPRScore
Command Injection78126014111251100,00%88,80%11,20%
Cross-Site Scripting79246078131455100,00%62,68%37,32%
Insecure Cookie61436031067100,00%0,00%100,00%
LDAP Injection9027052759100,00%84,38%15,63%
Path Traversal2212851811726896,24%86,67%9,57%
SQL Injection89272022210504100,00%90,52%9,48%
Trust Boundary Violation501830835126100,00%81,40%18,60%
Weak Encryption Algorithm32713006353246100,00%45,69%54,31%
Weak Hash Algorithm3288940107023668,99%0,00%68,99%
Weak Random Number33021802750493100,00%0,00%100,00%
XPath Injection64315011935100,00%95,00%5,00%
Totals*1370456227032740
Overall Results*96,84%57,74%39,10%

*-The Overall Results are averages across all the vulnerability categories. You can't compute these averages by simply calculating the TPR and FPR rates using the values in the Totals row. If you did that, categories with larger number of tests would carry more weight than categories with less tests. The proper calculation of the Overall Results is to add up all the TPR, FPR, and Score values, and then divide by the number of vulnerability categories, which is how they are calculated.

Key

Common Weakness Enumeration (CWE) The primary MITRE CWE number for this vulnerability category.
True Positive (TP) Tests with real vulnerabilities that were correctly reported as vulnerable by the tool.
False Negative (FN) Tests with real vulnerabilities that were not correctly reported as vulnerable by the tool.
True Negative (TN) Tests with fake vulnerabilities that were correctly not reported as vulnerable by the tool.
False Positive (FP) Tests with fake vulnerabilities that were incorrectly reported as vulnerable by the tool.
True Positive Rate (TPR) = TP / ( TP + FN ) The rate at which the tool correctly reports real vulnerabilities. Also referred to as Recall, as defined at Wikipedia.
False Positive Rate (FPR) = FP / ( FP + TN ) The rate at which the tool incorrectly reports fake vulnerabilities as real.
Score = TPR - FPR Normalized distance from the random guess line.