activity
20192022
collaborators

10 papers

cs.CR2022

FuzzingDriver: the Missing Dictionary to Increase Code Coverage in Fuzzers

Arash Ale Ebrahim, Mohammadreza Hazhirpasand, Oscar Nierstrasz +1

We propose a tool, called FuzzingDriver, to generate dictionary tokens for coverage-based greybox fuzzers (CGF) from the codebase of any target program. FuzzingDriver does not add…

cs.CR2021

Cryptography Vulnerabilities on HackerOne

Mohammadreza Hazhirpasand, Mohammad Ghafari

Previous studies have shown that cryptography is hard for developers to use and misusing cryptography leads to severe security vulnerabilities. We studied relevant vulnerability re…

cs.CR2021

Dazed and Confused: What's Wrong with Crypto Libraries?

Mohammadreza Hazhirpasand, Oscar Nierstrasz, Mohammad Ghafari

Recent studies have shown that developers have difficulties in using cryptographic APIs, which often led to security flaws. We are interested to tackle this matter by looking into…

cs.CR2021

Crypto Experts Advise What They Adopt

Mohammadreza Hazhirpasand, Oscar Nierstrasz, Mohammad Ghafari

Previous studies have shown that developers regularly seek advice on online forums to resolve their cryptography issues. We investigated whether users who are active in cryptograph…

cs.CR2021

Worrisome Patterns in Developers: A Survey in Cryptography

Mohammadreza Hazhirpasand, Oscar Nierstrasz, Mohammad Ghafari

We surveyed 97 developers who had used cryptography in open-source projects, in the hope of identifying developer security and cryptography practices. We asked them about individua…

cs.CR2021

Hurdles for Developers in Cryptography

Mohammadreza Hazhirpasand, Oscar Nierstrasz, Mohammadhossein Shabani +1

Prior research has shown that cryptography is hard to use for developers. We aim to understand what cryptography issues developers face in practice. We clustered 91954 cryptography…