activity
20192022
most citedFinding Security Threats That Matter: An Industrial Case Study

1 citations · 1 across the 4 of their papers we have counts for

collaborators

10 papers

cs.CR2022

GitHub Considered Harmful? Analyzing Open-Source Projects for the Automatic Generation of Cryptographic API Call Sequences

Catherine Tony, Nicolás E. Díaz Ferreyra, Riccardo Scandariato

GitHub is a popular data repository for code examples. It is being continuously used to train several AI-based tools to automatically generate code. However, the effectiveness of s…

cs.HC2022

Conversational DevBots for Secure Programming: An Empirical Study on SKF Chatbot

Catherine Tony, Mohana Balasubramanian, Nicolás E. Díaz Ferreyra +1

Conversational agents or chatbots are widely investigated and used across different fields including healthcare, education, and marketing. Still, the development of chatbots for as…

cs.SE2021

Secure Software Development in the Era of Fluid Multi-party Open Software and Services

Ivan Pashchenko, Riccardo Scandariato, Antonino Sabetta +1

Pushed by market forces, software development has become fast-paced. As a consequence, modern development projects are assembled from 3rd-party components. Security & privacy assur…

cs.CR2020

Contextualisation of Data Flow Diagrams for security analysis

Shamal Faily, Riccardo Scandariato, Adam Shostack +2

Data flow diagrams (DFDs) are popular for sketching systems for subsequent threat modelling. Their limited semantics make reasoning about them difficult, but enriching them endange…

cs.SE2020

Security Assurance Cases -- State of the Art of an Emerging Approach

Mazen Mohamad, Jan-Philipp Steghöfer, Riccardo Scandariato

Security Assurance Cases (SAC) are a form of structured argumentation used to reason about the security properties of a system. After the successful adoption of assurance cases for…

cs.SE2020

Cross-project Classification of Security-related Requirements

Mazen Mohamad, Jan-Philipp Steghöfer, Riccardo Scandariato

We investigate the feasibility of using a classifier for security-related requirements trained on requirement specifications available online. This is helpful in case different req…