3 citations · 6 across the 5 of their papers we have counts for
5 papers
VFCFinder: Seamlessly Pairing Security Advisories and Patches
Trevor Dunlap, Elizabeth Lin, William Enck +1
Security advisories are the primary channel of communication for discovered vulnerabilities in open-source software, but they often lack crucial information. Specifically, 63% of v…
SecretBench: A Dataset of Software Secrets
Setu Kumar Basak, Lorenzo Neil, Bradley Reaves +1
According to GitGuardian's monitoring of public GitHub repositories, the exposure of secrets (API keys and other credentials) increased two-fold in 2021 compared to 2020, totaling…
What Challenges Do Developers Face About Checked-in Secrets in Software Artifacts?
Setu Kumar Basak, Lorenzo Neil, Bradley Reaves +1
Throughout 2021, GitGuardian's monitoring of public GitHub repositories revealed a two-fold increase in the number of secrets (database credentials, API keys, and other credentials…
What are the Practices for Secret Management in Software Artifacts?
Setu Kumar Basak, Lorenzo Neil, Bradley Reaves +1
Throughout 2021, GitGuardian's monitoring of public GitHub repositories revealed a two-fold increase in the number of secrets (database credentials, API keys, and other credentials…
Retrofitting Applications with Provenance-Based Security Monitoring
Adam Bates, Kevin Butler, Alin Dobra +4
Data provenance is a valuable tool for detecting and preventing cyber attack, providing insight into the nature of suspicious events. For example, an administrator can use provenan…