Fetching the paper…
Reading the bibliography…
In this study, we investigate the limits of the current state of the art AI system for detecting buffer overflows and compare it with current static analysis tools.
P. Cousot and R. Cousot, “Abstract interpretation: a unified lattice model for static analysis of programs by construction or approximation of fixpoints,” in Proceedings of the 4th ACM SIGACT-SIGPLAN symposium on Principles of programming languages . ACM, 1977, pp. 238–252
1977
Earlier work this paper cites.
E. M. Voorhees and D. M. Tice, “Building a Question Answering Test Collection,” in Proceedings of the 23rd Annual International ACM SIGIR Conference on Research and Development in Information Retrieval , ser. SIGIR ’00. New York, NY, USA: ACM, 2000, pp. 200–207
2000
Earlier work this paper cites.
B. Chess and G. McGraw, “Static analysis for security,” IEEE Security & Privacy , vol. 2, no. 6, pp. 76–79, 2004
2004
Earlier work this paper cites.
M. Zitser, R. Lippmann, and T. Leek, “Testing Static Analysis Tools Using Exploitable Buffer Overflows from Open Source Code,” SIGSOFT Softw. Eng. Notes , vol. 29, no. 6, pp. 97–106, Oct. 2004
2004
Earlier work this paper cites.
S. Wagner, J. Jürjens, C. Koller, and P. Trischberger, “Comparing Bug Finding Tools with Reviews and Tests,” in Testing of Communicating Systems . Springer Berlin Heidelberg, 2005, pp. 40–55
2005
Earlier work this paper cites.
K. Kratkiewicz and R. Lippmann, “Using a Diagnostic Corpus of C Programs to Evaluate Buffer Overflow Detection by Static Analysis Tools,” Workshop on the Evaluation of Software Defect Detection Tools , 2005
2005
Earlier work this paper cites.
P. E. Black, “SAMATE’s contribution to information assurance,” NIST Special Publication , vol. 500, no. 264, p. 2, 2006
2006
Earlier work this paper cites.
N. Ayewah, W. Pugh, J. D. Morgenthaler, J. Penix, and Y. Zhou, “Evaluating Static Analysis Defect Warnings on Production Software,” in Proceedings of the 7th ACM SIGPLAN-SIGSOFT Workshop on Program Analysis for Software Tools and Engineering , ser. PASTE ’07. New York, NY, USA: ACM, 2007, pp. 1–8
2007
Earlier work this paper cites.
P. Emanuelsson and U. Nilsson, “A Comparative Study of Industrial Static Analysis Tools,” Electronic notes in theoretical computer science , vol. 217, pp. 5–21, Jul. 2008
2008
Earlier work this paper cites.
F. Logozzo and M. Fähndrich, “Pentagons: a weakly relational abstract domain for the efficient validation of array accesses,” in Proceedings of the 2008 ACM symposium on Applied computing . ACM, 2008, pp. 184–188
2008
Earlier work this paper cites.
P. Saxena, P. Poosankam, S. McCamant, and D. Song, “Loop-extended symbolic execution on binary programs,” in Proceedings of the eighteenth international symposium on Software testing and analysis . ACM, 2009, pp. 225–236
2009
Earlier work this paper cites.
P. Cousot, R. Cousot, J. Feret, L. Mauborgne, A. Miné, and X. Rival, “Why does astrée scale up?” Formal Methods in System Design , vol. 35, no. 3, pp. 229–264, 2009
2009
Earlier work this paper cites.
V. Okun, R. Gaucher, and P. E. Black, “Static analysis tool exposition (SATE) 2008,” NIST Special Publication , vol. 500, p. 279, 2009
2009
Earlier work this paper cites.
V. Okun, A. Delaitre, and P. E. Black, “The second static analysis tool exposition (SATE) 2009,” NIST Special Publication , pp. 500–287, 2010
2010
Earlier work this paper cites.
——, “Report on the third static analysis tool exposition (SATE 2010),” NIST Special Publication , pp. 500–283, 2011
2011
Earlier work this paper cites.
T. Boland and P. E. Black, “Juliet 1.1 C/C++ and Java Test Suite,” Computer , no. 10, pp. 88–90, Oct. 2012
2012
Earlier work this paper cites.
P. Ram and A. G. Gray, “Maximum inner-product search using cone trees,” in Proceedings of the 18th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining , ser. KDD ’12. New York, NY, USA: ACM, 2012, pp. 931–939. [Online]. Available: http://doi.acm.org/10.1145/2339530.2339677
2012
Earlier work this paper cites.
B. Johnson, Y. Song, E. Murphy-Hill, and R. Bowdidge, “Why Don’T Software Developers Use Static Analysis Tools to Find Bugs?” in Proceedings of the 2013 International Conference on Software Engineering , ser. ICSE ’13. Piscataway, NJ, USA: IEEE Press, 2013, pp. 672–681
2013
Cited alongside, same era.
W. Y. Zou, R. Socher, D. M. Cer, and C. D. Manning, “Bilingual word embeddings for phrase-based machine translation,” in EMNLP , 2013
2013
Cited alongside, same era.
——, “Report on the static analysis tool exposition (sate) iv,” NIST Special Publication , vol. 500, p. 297, 2013
2013
Cited alongside, same era.
H. Nazaré, I. Maffra, W. Santos, L. Barbosa, L. Gonnord, and F. M. Quintão Pereira, “Validation of memory accesses through symbolic analyses,” in ACM SIGPLAN Notices , vol. 49, no. 10. ACM, 2014, pp. 791–809
2014
Cited alongside, same era.
B. Dolan-Gavitt, P. Hulin, E. Kirda, T. Leek, A. Mambretti, W. Robertson, F. Ulrich, and R. Whelan, “LAVA: Large-Scale Automated Vulnerability Addition,” in 2016 IEEE Symposium on Security and Privacy (SP) , May 2016, pp. 110–121
2016
Later among the works it cites.
2017
Later among the works it cites.
M. Allamanis, E. T. Barr, P. Devanbu, and C. Sutton, “A Survey of Machine Learning for Big Code and Naturalness,” Sep. 2017
2017
Later among the works it cites.
D. Coughlin, “[cfe-dev] handling of loops in the clang static analyzer,” 2017, http://lists.llvm.org/pipermail/cfe-dev/2017-February/052818.html
2017
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2014
Cited alongside, same era.
N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, and R. Salakhutdinov, “Dropout: a simple way to prevent neural networks from overfitting,” Journal of machine learning research: JMLR , vol. 15, no. 1, pp. 1929–1958, 2014
2014
Cited alongside, same era.
D. P. Kingma and J. Ba, “Adam: A Method for Stochastic Optimization,” Dec. 2014
2014
Cited alongside, same era.
K. Goseva-Popstojanova and A. Perhinschi, “On the capability of static code analysis to detect security vulnerabilities,” Information and Software Technology , vol. 68, pp. 18–33, Dec. 2015
2015
Cited alongside, same era.
2015
Cited alongside, same era.
2015
Cited alongside, same era.
F. Kirchner, N. Kosmatov, V. Prevosto, J. Signoles, and B. Yakobowski, “Frama-c: A software analysis perspective,” Formal Aspects of Computing , vol. 27, no. 3, pp. 573–609, 2015
2015
Cited alongside, same era.
2015
Cited alongside, same era.
I. Pashchenko, S. Dashevskyi, and F. Massacci, “Delta-bench: Differential Benchmark for Static Analysis Security Testing Tools,” in Proceedings of the 11th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement , ser. ESEM ’17. Piscataway, NJ, USA: IEEE Press, 2017, pp. 163–168
2017
Later among the works it cites.
2017
Later among the works it cites.
P. E. Black, “A Software Assurance Reference Dataset: Thousands of Programs With Known Bugs,” Journal of research of the National Institute of Standards and Technology , vol. 123, Apr. 2018
2018
Closest in time.
——, “Juliet 1.3 test suite: changes from 1.2,” National Institute of Standards and Technology, Gaithersburg, MD, Tech. Rep., Jun. 2018
2018
Closest in time.
“The Stanford Question Answering Dataset,” https://rajpurkar.github.io/SQuAD-explorer/ , accessed: 2018-8-21
2018
Closest in time.
A. W. Yu, D. Dohan, M.-T. Luong, R. Zhao, K. Chen, M. Norouzi, and Q. V. Le, “QANet: Combining Local Convolution with Global Self-Attention for Reading Comprehension,” Apr. 2018
2018
Closest in time.
U. Alon, M. Zilberstein, O. Levy, and E. Yahav, “code2vec: Learning Distributed Representations of Code,” Mar. 2018
2018
Closest in time.
É. Payet and F. Spoto, “Checking array bounds by abstract interpretation and symbolic expressions,” in International Joint Conference on Automated Reasoning . Springer, 2018, pp. 706–722
2018
Closest in time.
R. Baldoni, E. Coppa, D. C. D’elia, C. Demetrescu, and I. Finocchi, “A survey of symbolic execution techniques,” ACM Computing Surveys (CSUR) , vol. 51, no. 3, p. 50, 2018
2018
Closest in time.
A. Trask, F. Hill, S. Reed, J. Rae, C. Dyer, and P. Blunsom, “Neural Arithmetic Logic Units,” Aug. 2018
2018
Closest in time.
R. L. Russell, L. Kim, L. H. Hamilton, T. Lazovich, J. A. Harer, O. Ozdemir, P. M. Ellingwood, and M. W. McConley, “Automated Vulnerability Detection in Source Code Using Deep Representation Learning,” Jul. 2018
2018
Closest in time.
“STONESOUP,” https://www.iarpa.gov/index.php/research-programs/stonesoup , accessed: 2018-8-20
2018
Closest in time.