47 citations · 99 across the 9 of their papers we have counts for
22 papers
FuzzingDriver: the Missing Dictionary to Increase Code Coverage in Fuzzers
Arash Ale Ebrahim, Mohammadreza Hazhirpasand, Oscar Nierstrasz +1
We propose a tool, called FuzzingDriver, to generate dictionary tokens for coverage-based greybox fuzzers (CGF) from the codebase of any target program. FuzzingDriver does not add…
Security Header Fields in HTTP Clients
Pascal Gadient, Oscar Nierstrasz, Mohammad Ghafari
HTTP headers are commonly used to establish web communications, and some of them are relevant for security. However, we have only little information about the usage and support of…
Phish What You Wish
Pascal Gadient, Pascal Gerig, Oscar Nierstrasz +1
IT professionals have no simple tool to create phishing websites and raise the awareness of users. We developed a prototype that can dynamically mimic websites by using enriched sc…
Dazed and Confused: What's Wrong with Crypto Libraries?
Mohammadreza Hazhirpasand, Oscar Nierstrasz, Mohammad Ghafari
Recent studies have shown that developers have difficulties in using cryptographic APIs, which often led to security flaws. We are interested to tackle this matter by looking into…
Crypto Experts Advise What They Adopt
Mohammadreza Hazhirpasand, Oscar Nierstrasz, Mohammad Ghafari
Previous studies have shown that developers regularly seek advice on online forums to resolve their cryptography issues. We investigated whether users who are active in cryptograph…
Worrisome Patterns in Developers: A Survey in Cryptography
Mohammadreza Hazhirpasand, Oscar Nierstrasz, Mohammad Ghafari
We surveyed 97 developers who had used cryptography in open-source projects, in the hope of identifying developer security and cryptography practices. We asked them about individua…