4 papers
Mutation-based Evaluation of Cryptographic API Misuse Detectors
Amit Seal Ami, Scott Marsden, Kevin Moran +2
The correct use of cryptography is central to ensuring data security in modern software systems. Hence, several academic and commercial static analysis tools have been developed fo…
"False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
Amit Seal Ami, Kevin Moran, Denys Poshyvanyk +1
The demand for automated security analysis techniques, such as static analysis based security testing (SAST) tools continues to increase. To develop SASTs that are effectively leve…
Toward a Theory of Causation for Interpreting Neural Code Models
David N. Palacio, Alejandro Velasco, Nathan Cooper +3
Neural Language Models of Code, or Neural Code Models (NCMs), are rapidly progressing from research prototypes to commercial developer tools. As such, understanding the capabilitie…
"The Law Doesn't Work Like a Computer": Exploring Software Licensing Issues Faced by Legal Practitioners
Nathan Wintersgill, Trevor Stalnaker, Laura A. Heymann +2
Most modern software products incorporate open source components, which requires compliance with each component's licenses. As noncompliance can lead to significant repercussions,…