4.3 Article

Being the Developers' Friend: Our Experience Developing a High-Precision Tool for Secure Coding

Related references

Note: Only part of the references are listed.
Article Computer Science, Software Engineering

Evaluation of Static Vulnerability Detection Tools With Java Cryptographic API Benchmarks

Sharmin Afrose et al.

IEEE TRANSACTIONS ON SOFTWARE ENGINEERING (2022)

Article Computer Science, Software Engineering

CrySL: An Extensible Approach to Validating the Correct Usage of Cryptographic APIs

Stefan Krueger et al.

Summary: Studies have shown that a majority of Java and Android applications misuse cryptographic libraries, leading to data security breaches. CrySL is a specification language that helps bridge the cognitive gap between cryptography experts and developers. CrySL allows experts to specify secure usage of cryptographic libraries and a compiler is implemented to analyze Java and Android applications for compliance with these rules.

IEEE TRANSACTIONS ON SOFTWARE ENGINEERING (2021)

Proceedings Paper Computer Science, Theory & Methods

Coding Practices and Recommendations of Spring Security for Enterprise Applications

Mazharul Islam et al.

2020 IEEE SECURE DEVELOPMENT (SECDEV 2020) (2020)

Proceedings Paper Computer Science, Information Systems

CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java Projects

Sazzadur Rahaman et al.

PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19) (2019)

Article Computer Science, Hardware & Architecture

Where Did I Leave My Keys. Lessons from the Juniper Dual EC Incident

Stephen Checkoway et al.

COMMUNICATIONS OF THE ACM (2018)

Proceedings Paper Computer Science, Software Engineering

Secure Coding Practices in Java: Challenges and Vulnerabilities

Na Meng et al.

PROCEEDINGS 2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE) (2018)

Proceedings Paper Computer Science, Information Systems

A Stitch in Time: Supporting Android Developers in Writing Secure Code

Duc Cuong Nguyen et al.

CCS'17: PROCEEDINGS OF THE 2017 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (2017)

Proceedings Paper Computer Science, Information Systems

Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application Security

Felix Fischer et al.

2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP) (2017)

Proceedings Paper Computer Science, Information Systems

Build It, Break It, Fix It: Contesting Secure Development

Andrew Ruef et al.

CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (2016)