20 citations · 35 across the 4 of their papers we have counts for
4 papers
ChatGPT's Potential in Cryptography Misuse Detection: A Comparative Analysis with Static Analysis Tools
Ehsan Firouzi, Mohammad Ghafari, Mike Ebrahimi
The correct adoption of cryptography APIs is challenging for mainstream developers, often resulting in widespread API misuse. Meanwhile, cryptography misuse detectors have demonstr…
From Struggle to Simplicity with a Usable and Secure API for Encryption in Java
Ehsan Firouzi, Ammar Mansuri, Mohammad Ghafari +1
Cryptography misuses are prevalent in the wild. Crypto APIs are hard to use for developers, and static analysis tools do not detect every misuse. We developed SafEncrypt, an API th…
Mining REST APIs for Potential Mass Assignment Vulnerabilities
Arash Mazidi, Davide Corradini, Mohammad Ghafari
REST APIs have a pivotal role in accessing protected resources. Despite the availability of security testing tools, mass assignment vulnerabilities are common in REST APIs, leading…
LLM Security Guard for Code
Arya Kavian, Mohammad Mehdi Pourhashem Kallehbasti, Sajjad Kazemi +2
Many developers rely on Large Language Models (LLMs) to facilitate software development. Nevertheless, these models have exhibited limited capabilities in the security domain. We i…