activity
20202022
collaborators

6 papers

cs.SE2022

Noisy Label Learning for Security Defects

Roland Croft, M. Ali Babar, Huaming Chen

Data-driven software engineering processes, such as vulnerability prediction heavily rely on the quality of the data used. In this paper, we observe that it is infeasible to obtain…

cs.CR2022

SmartValidator: A Framework for Automatic Identification and Classification of Cyber Threat Data

Chadni Islam, M. Ali Babar, Roland Croft +1

A wide variety of Cyber Threat Information (CTI) is used by Security Operation Centres (SOCs) to perform validation of security incidents and alerts. Security experts manually defi…

cs.SE2022

An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources

Roland Croft, M. Ali Babar, Li Li

Software Vulnerability (SV) severity assessment is a vital task for informing SV remediation and triage. Ranking of SV severity scores is often used to advise prioritization of pat…

cs.SE2021

DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task Learning

Triet H. M. Le, David Hin, Roland Croft +1

It is increasingly suggested to identify Software Vulnerabilities (SVs) in code commits to give early warnings about potential security risks. However, there is a lack of effort to…

cs.SE2021

An Empirical Study of Rule-Based and Learning-Based Approaches for Static Application Security Testing

Roland Croft, Dominic Newlands, Ziyu Chen +1

Background: Static Application Security Testing (SAST) tools purport to assist developers in detecting security issues in source code. These tools typically use rule-based approach…

cs.SE2020

PUMiner: Mining Security Posts from Developer Question and Answer Websites with PU Learning

Triet H. M. Le, David Hin, Roland Croft +1

Security is an increasing concern in software development. Developer Question and Answer (Q&A) websites provide a large amount of security discussion. Existing studies have used hu…