77 citations · 147 across the 6 of their papers we have counts for
13 papers
A Comparative Study of Vulnerability Reporting by Software Composition Analysis Tools
Nasif Imtiaz, Seaver Thorne, Laurie Williams
Background: Modern software uses many third-party libraries and frameworks as dependencies. Known vulnerabilities in these dependencies are a potential security risk. Software comp…
Memory Error Detection in Security Testing
Nasif Imtiaz, Laurie Williams
We study 10 C/C++ projects that have been using a static analysis security testing tool. We analyze the historical scan reports generated by the tool and study how frequently memor…
Structuring a Comprehensive Software Security Course Around the OWASP Application Security Verification Standard
Sarah Elder, Nusrat Zahan, Val Kozarev +3
Lack of security expertise among software practitioners is a problem with many implications. First, there is a deficit of security professionals to meet current needs. Additionally…
Omni: Automated Ensemble with Unexpected Models against Adversarial Evasion Attack
Rui Shu, Tianpei Xia, Laurie Williams +1
Background: Machine learning-based security detection models have become prevalent in modern malware and intrusion detection systems. However, previous studies show that such model…
The 'as Code' Activities: Development Anti-patterns for Infrastructure as Code
Akond Rahman, Effat Farhana, Laurie Williams
Context: The 'as code' suffix in infrastructure as code (IaC) refers to applying software engineering activities, such as version control, to maintain IaC scripts. Without the appl…
How to Better Distinguish Security Bug Reports (using Dual Hyperparameter Optimization
Rui Shu, Tianpei Xia, Jianfeng Chen +2
Background: In order that the general public is not vulnerable to hackers, security bug reports need to be handled by small groups of engineers before being widely discussed. But l…