4 papers
Security Vulnerability Patterns in AI-Generated Code: A Cross-Model Comparative Study
Shanna M. Kahn, John D. Hastings
LLM-based coding tools enable non-expert users to generate routine automation scripts that may enter enterprise workflows without meaningful security review. This study examines th…
Unsupervised Baseline Clustering and Incremental Adaptation for IoT Device Traffic Profiling
Sean M. Alderman, John D. Hastings
The growth and heterogeneity of IoT devices create security challenges where static identification models can degrade as traffic evolves. This paper presents a two-stage, flow-feat…
Advancing DevSecOps in SMEs: Challenges and Best Practices for Secure CI/CD Pipelines
Jayaprakashreddy Cheenepalli, John D. Hastings, Khandaker Mamun Ahmed +1
This study evaluates the adoption of DevSecOps among small and medium-sized enterprises (SMEs), identifying key challenges, best practices, and future trends. Through a mixed metho…
Impact of Data Snooping on Deep Learning Models for Locating Vulnerabilities in Lifted Code
Gary A. McCully, John D. Hastings, Shengjie Xu
This study examines the impact of data snooping on neural networks used to detect vulnerabilities in lifted code, and builds on previous research that used word2vec and unidirectio…