6 citations · 6 across the 1 of their papers we have counts for
3 papers
How Quickly Do Development Teams Update Their Vulnerable Dependencies?
Imranur Rahman, Ranindya Paramitha, Nusrat Zahan +2
Industry practitioners are increasingly concerned with software that contains vulnerable versions of third-party dependencies that are included both directly and transitively. To a…
Assumptions to Evidence: Evaluating Security Practices Adoption and Their Impact on Outcomes in the npm Ecosystem
Nusrat Zahan, Imranur Rahman, Laurie Williams
Practitioners often struggle with the overwhelming number of security practices outlined in cybersecurity frameworks for risk mitigation. Given the limited budget, time, and resour…
Leveraging Large Language Models to Detect npm Malicious Packages
Nusrat Zahan, Philipp Burckhardt, Mikola Lysenko +2
Existing malicious code detection techniques demand the integration of multiple tools to detect different malware patterns, often suffering from high misclassification rates. There…