89 citations · 292 across the 27 of their papers we have counts for
19 papers · 1 filter
Collaborative Application Security Testing for DevSecOps: An Empirical Analysis of Challenges, Best Practices and Tool Support
Roshan Namal Rajapakse, Mansooreh Zahedi, Muhammad Ali Babar
DevSecOps is a software development paradigm that places a high emphasis on the culture of collaboration between developers (Dev), security (Sec) and operations (Ops) teams to deli…
LogGD:Detecting Anomalies from System Logs by Graph Neural Networks
Yongzheng Xie, Hongyu Zhang, Muhammad Ali Babar
Log analysis is one of the main techniques engineers use to troubleshoot faults of large-scale software systems. During the past decades, many log analysis approaches have been pro…
Noisy Label Learning for Security Defects
Roland Croft, M. Ali Babar, Huaming Chen
Data-driven software engineering processes, such as vulnerability prediction heavily rely on the quality of the data used. In this paper, we observe that it is infeasible to obtain…
On the Use of Fine-grained Vulnerable Code Statements for Software Vulnerability Assessment Models
Triet H. M. Le, M. Ali Babar
Many studies have developed Machine Learning (ML) approaches to detect Software Vulnerabilities (SVs) in functions and fine-grained code statements that cause such SVs. However, th…
An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources
Roland Croft, M. Ali Babar, Li Li
Software Vulnerability (SV) severity assessment is a vital task for informing SV remediation and triage. Ranking of SV severity scores is often used to advise prioritization of pat…
LogDP: Combining Dependency and Proximity for Log-based Anomaly Detection
Yongzheng Xie, Hongyu Zhang, Bo Zhang +2
Log analysis is an important technique that engineers use for troubleshooting faults of large-scale service-oriented systems. In this study, we propose a novel semi-supervised log-…