6 papers
Noisy Label Learning for Security Defects
Roland Croft, M. Ali Babar, Huaming Chen
Data-driven software engineering processes, such as vulnerability prediction heavily rely on the quality of the data used. In this paper, we observe that it is infeasible to obtain…
SmartValidator: A Framework for Automatic Identification and Classification of Cyber Threat Data
Chadni Islam, M. Ali Babar, Roland Croft +1
A wide variety of Cyber Threat Information (CTI) is used by Security Operation Centres (SOCs) to perform validation of security incidents and alerts. Security experts manually defi…
An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources
Roland Croft, M. Ali Babar, Li Li
Software Vulnerability (SV) severity assessment is a vital task for informing SV remediation and triage. Ranking of SV severity scores is often used to advise prioritization of pat…
DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task Learning
Triet H. M. Le, David Hin, Roland Croft +1
It is increasingly suggested to identify Software Vulnerabilities (SVs) in code commits to give early warnings about potential security risks. However, there is a lack of effort to…
An Empirical Study of Rule-Based and Learning-Based Approaches for Static Application Security Testing
Roland Croft, Dominic Newlands, Ziyu Chen +1
Background: Static Application Security Testing (SAST) tools purport to assist developers in detecting security issues in source code. These tools typically use rule-based approach…
PUMiner: Mining Security Posts from Developer Question and Answer Websites with PU Learning
Triet H. M. Le, David Hin, Roland Croft +1
Security is an increasing concern in software development. Developer Question and Answer (Q&A) websites provide a large amount of security discussion. Existing studies have used hu…