Ata Seren, Analysis and Comparison of Static Application Security Testing Tools and Common Tool Mechanisms
This thesis presents a systematic evaluation of Static Application Security Testing (SAST) tools. Related studies mostly use synthetic codebases and per-vulnerability evaluation methods. In this study, both synthetic benchmarks and real-world intentionally vulnerable applications are tested against tools, along with per-issue evaluation. Conducted experiments measure various metrics and explain these results with reasons behind them. In addition to quantitative results, qualitative features and internal mechanisms of tools are examined to further explain results and observed performance differences. The results demonstrate the difference between evaluation models and tool effectivenes. Overall, thesis offers practical insights for SAST tool research and selection.
Date: 14.04.2026 / 11:00 Place: Cisco Lab









