activity
20172022
most citedSecure Coding Practices in Java: Challenges and Vulnerabilities

22 citations · 46 across the 9 of their papers we have counts for

collaborators
Showing cs.CRShow all

11 papers · 1 filter

cs.CR20221 cited

Example-Based Vulnerability Detection and Repair in Java Code

Ying Zhang, Ya Xiao, Md Mahir Asef Kabir +3

The Java libraries JCA and JSSE offer cryptographic APIs to facilitate secure coding. When developers misuse some of the APIs, their code becomes vulnerable to cyber-attacks. To el…

cs.CR20212 cited

Data-Driven Vulnerability Detection and Repair in Java Code

Ying Zhang, Mahir Kabir, Ya Xiao +3

Java platform provides various APIs to facilitate secure coding. However, correctly using security APIs is usually challenging for developers who lack cybersecurity training. Prior…

cs.CR20203 cited

Coding Practices and Recommendations of Spring Security for Enterprise Applications

Mazharul Islam, Sazzadur Rahaman, Na Meng +4

Spring security is tremendously popular among practitioners for its ease of use to secure enterprise applications. In this paper, we study the application framework misconfiguratio…

cs.CR2020

Deep Learning-Based Anomaly Detection in Cyber-Physical Systems: Progress and Opportunities

Yuan Luo, Ya Xiao, Long Cheng +2

Anomaly detection is crucial to ensure the security of cyber-physical systems (CPS). However, due to the increasing complexity of CPSs and more sophisticated attacks, conventional…

cs.CR202011 cited

Security Certification in Payment Card Industry: Testbeds, Measurements, and Recommendations

Sazzadur Rahaman, Gang Wang, Danfeng +1

The massive payment card industry (PCI) involves various entities such as merchants, issuer banks, acquirer banks, and card brands. Ensuring security for all entities that process…

cs.CR20192 cited

Neural Cryptanalysis: Metrics, Methodology, and Applications in CPS Ciphers

Ya Xiao, Qingying Hao, Danfeng +1

Many real-world cyber-physical systems (CPS) use proprietary cipher algorithms. In this work, we describe an easy-to-use black-box security evaluation approach to measure the stren…