2 papers
cs.SE2021
Test Suites as a Source of Training Data for Static Analysis Alert Classifiers
Lori Flynn, William Snavely, Zachary Kurtz
Flaw-finding static analysis tools typically generate large volumes of code flaw alerts including many false positives. To save on human effort to triage these alerts, a significan…
cs.CR2018
Towards security defect prediction with AI
Carson D. Sestili, William S. Snavely, Nathan M. VanHoudnos
In this study, we investigate the limits of the current state of the art AI system for detecting buffer overflows and compare it with current static analysis tools. To do so, we de…