4 citations · 7 across the 7 of their papers we have counts for
12 papers · 1 filter
CauSec: Unboxing the Causal Drivers of Static Vulnerability Analysis Performance
Md Akram Khan, Daniel Rodriguez-Cardenas, Alejandro Velasco +2
Static Application Security Testing (SAST) tools are widely used in both industry and academia. Such tools often make design choices that sacrifice detection to achieve higher perf…
From base cases to backdoors: An Empirical Study of Unnatural Crypto-API Misuse
Victor Olaiya, Adwait Nadkarni
Tools focused on cryptographic API misuse often detect the most basic expressions of the vulnerable use, and are unable to detect non-trivial variants. The question of whether tool…
Helion: Enabling Natural Testing of Smart Homes
Prianka Mandal, Sunil Manandhar, Kaushal Kafle +3
Prior work has developed numerous systems that test the security and safety of smart homes. For these systems to be applicable in practice, it is necessary to test them with realis…
MASC: A Tool for Mutation-Based Evaluation of Static Crypto-API Misuse Detectors
Amit Seal Ami, Syed Yusuf Ahmed, Radowan Mahmud Redoy +5
While software engineers are optimistically adopting crypto-API misuse detectors (or crypto-detectors) in their software development cycles, this momentum must be accompanied by a…
"False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
Amit Seal Ami, Kevin Moran, Denys Poshyvanyk +1
The demand for automated security analysis techniques, such as static analysis based security testing (SAST) tools continues to increase. To develop SASTs that are effectively leve…
Towards Practical Integrity in the Smart Home with HomeEndorser
Kaushal Kafle, Kirti Jagtap, Mansoor Ahmed-Rengers +2
Home automation in modern smart home platforms is often facilitated using trigger-action routines. While such routines enable flexible automation, they also lead to an instance of…