Fetching the paper…
Reading the bibliography…
Context: Cryptographic APIs are often misused in real-world applications.
Undecidability of Context-Sensitive Data-Dependence Analysis
Thomas Reps. 2000 · 2000
Earlier work this paper cites.
Procedures for performing systematic reviews
Barbara Kitchenham. 2004 · 2004
Earlier work this paper cites.
The DaCapo Benchmarks: Java Benchmarking Development and Analysis. In 21st ACM SIGPLAN conference on Object-oriented programming systems, languages, and applications (OOPSLA) . ACM
S. Blackburn, R. Garner, C. Hoffmann, A. Khang, K. McKinley, R. Bentzur, A. Diwan, D. Feinberg, D. Frampton, S. Guyer, M. Hirzel, A. Hosking, and et. al. 2006 · 2006
Earlier work this paper cites.
The Qualitas Corpus: A curated collection of Java code for empirical studies. In Asia Pacific Software Engineering Conference (APSEC) . IEEE
Ewan Tempero, Craig Anslow, Jens Dietrich, Ted Han, Jing Li, Markus Lumpe, Hayden Melton, and James Noble. 2010 · 2010
Earlier work this paper cites.
SonarQube
SonarSource. 2022 · 2011
Earlier work this paper cites.
PMD - source code analyzer
2022b · 2012
Earlier work this paper cites.
Boa: A language and infrastructure for analyzing ultra-large-scale software repositories. In ACM 35th International Conference on Software Engineering (ICSE) . ACM
Robert Dyer, Hoan Anh Nguyen, Hridesh Rajan, and Tien N Nguyen. 2013 · 2013
Earlier work this paper cites.
An empirical study of cryptographic misuse in android applications. In 2013 ACM SIGSAC conference on Computer and Communications security (CCS) . ACM
Manuel Egele, David Brumley, Yanick Fratantonio, and Christopher Kruegel. 2013 · 2013
Earlier work this paper cites.
Why don’t software developers use static analysis tools to find bugs?. In ACM 35th International Conference on Software Engineering (ICSE) . ACM
B. Johnson, Y. Song, E. Murphy-Hill, and R. Bowdidge. 2013 · 2013
Earlier work this paper cites.
A review paper of message digest 5 (MD5). In International Journal of Modern Engineering & Management Research , Vol. 1
Alok Kumar Kasgar, Mukesh Kumar Dhariwal, Neeraj Tantubay, and Hina Malviya. 2013 · 2013
Earlier work this paper cites.
Why does cryptographic software fail? A case study and open problems. In 5th Asia-Pacific Workshop on Systems (APSys) . ACM
David Lazar, Haogang Chen, Xi Wang, and Nickolai Zeldovich. 2014 · 2014
Earlier work this paper cites.
Amandroid: A precise and general inter-component data flow analysis framework for security vetting of android apps. In 2014 ACM SIGSAC conference on Computer and Communications security (CCS) . ACM
Fengguo Wei, Sankardas Roy, and Xinming Ou. 2014 · 2014
Earlier work this paper cites.
OWASP ZAP
2022a · 2015
Earlier work this paper cites.
VisualCodeGrepper
2022d · 2015
Earlier work this paper cites.
Mobile Security Framework (MobSF)
Aijn Abraham, Magaofei, Matan Dobrushin, and Vincent Nadal. 2022 · 2015
Earlier work this paper cites.
In defense of soundiness: A manifesto
Benjamin Livshits, Manu Sridharan, Yannis Smaragdakis, Ondřej Lhoták, J Nelson Amaral, Bor-Yuh Evan Chang, Samuel Z Guyer, Uday P Khedker, Anders Møller, and Dimitrios Vardoulakis. 2015 · 2015
Earlier work this paper cites.
spotbugs/spotbugs
2022c · 2016
Earlier work this paper cites.
MUBench: A benchmark for API-misuse detectors. In In 2016 ACM 13th International Conference on Mining Software Repositories (MSR) . ACM
Sven Amann, Sarah Nadi, Hoan A Nguyen, Tien N Nguyen, and Mira Mezini. 2016 · 2016
Cited alongside, same era.
What Developers Want and Need from Program Analysis: An Empirical Study. In 31st IEEE/ACM International Conference on Automated Software Engineering (ASE) . ACM
Maria Christakis and Christian Bird. 2016 · 2016
Cited alongside, same era.
Toward an Automated Benchmark Management System. In 5th ACM SIGPLAN International Workshop on State Of the Art in Program Analysis (SOAP) . ACM
Lisa Nguyen Quang Do, Michael Eichberg, and Eric Bodden. 2016 · 2016
Cited alongside, same era.
Jumping through hoops: Why do Java developers struggle with cryptography APIs?. In 38th IEEE/ACM International Conference on Software Engineering (ICSE) . ACM
Sarah Nadi, Stefan Krüger, Mira Mezini, and Eric Bodden. 2016 · 2016
Cited alongside, same era.
Cryptoguard: High precision detection of cryptographic vulnerabilities in massive-sized java projects. In 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS) . ACM
Sazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon, Ke Tian, Miles Frantz, Murat Kantarcioglu, and Danfeng Yao. 2019 · 2019
Later among the works it cites.
A dataset of parametric cryptographic misuses. In 16th International Conference on Mining Software Repositories (MSR) . IEEE/ACM
Anna-Katharina Wickert, Michael Reif, Michael Eichberg, Anam Dodhy, and Mira Mezini. 2019 · 2019
Later among the works it cites.
CryptoREX: Large-scale Analysis of Cryptographic Misuse in IoT Devices. In 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID) . USENIX Association
Li Zhang, Jiongyi Chen, Wenrui Diao, Shanqing Guo, Jian Weng, and Kehuan Zhang. 2019 · 2019
Later among the works it cites.
Are free android app security analysis tools effective in detecting known vulnerabilities?. In Empirical Software Engineering , Vol. 25. Springer
Venkatesh-Prasad Ranganath and Joydeep Mitra. 2020 · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Fausto Spoto. 2016 · 2016
Cited alongside, same era.
Practical evaluation of static analysis tools for cryptography: Benchmarking method and case study. In IEEE 28th International Symposium on Software Reliability Engineering (ISSRE) . IEEE
Alexandre Braga, Ricardo Dahab, Nuno Antunes, Nuno Laranjeiro, and Marco Vieira. 2017 · 2017
Cited alongside, same era.
Security analysis of the OWASP benchmark with Julia
Elisa Burato, Pietro Ferrara, and Fausto Spoto. 2017 · 2017
Cited alongside, same era.
Static analysis of android apps: A systematic literature review. In Information and Software Technology , Vol. 88
Li Li, Tegawendé F. Bissyandé, Mike Papadakis, Siegfried Rasthofer, Alexandre Bartel, Damien Octeau, Jacques Klein, and Le Traon. 2017 · 2017
Cited alongside, same era.
Ghera: A repository of android app vulnerability benchmarks. In 13th International Conference on Predictive Models and Data Analytics in Software Engineering (PROMISE) . ACM
Joydeep Mitra and Venkatesh-Prasad Ranganath. 2017 · 2017
Cited alongside, same era.
Comparative evaluation of the state-of-art requirements-based test case generation approaches. In International Journal on Advanced Science, Engineering and Information Technology , Vol. 7
Ahmad Mustafa, Wan MN Wan-Kadir, and I Ibrahim. 2017 · 2017
Cited alongside, same era.
A stitch in time: Supporting android developers in writingsecure code. In 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS) . ACM
Duc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes, Charles Weir, and Sascha Fahl. 2017 · 2017
Cited alongside, same era.
Hermes: assessment and creation of effective test corpora. In 6th ACM SIGPLAN International Workshop on State Of the Art in Program Analysis (SOAP) . ACM
Michael Reif, Michael Eichberg, Ben Hermann, and Mira Mezini. 2017 · 2017
Cited alongside, same era.
Python Crypto Misuses in the Wild. In 15th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM) . ACM
Anna-Katharina Wickert, Lars Baumgärtner, Florian Breitfelder, and Mira Mezini. 2021 · 2021
Later among the works it cites.
AppCritique
Booz Allen. 2022 · 2022
Closest in time.
How can I check the integrity of an object uploaded to Amazon S3?
Amazon Web Services (AWS). 2022 · 2022
Closest in time.
Find Security Bugs 1.11.0
Philippe Arteau. 2020 · 2022
Closest in time.
BSI TR-02102-1: "Cryptographic Mechanisms: Recommendations and Key Lengths"
German Federal Office for Information Security (BSI). 2022 · 2022
Closest in time.
Xanitizer
RIGS IT GmbH. 2022 · 2022
Closest in time.
Coverity Scan - Static Analysis
Synopsys Inc. 2022 · 2022
Closest in time.
Devknox - Security Plugin for Android Studio
XYSEC Labs. 2022 · 2022
Closest in time.
SP 800-175B Rev. 1 Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms
National Institute of Standards and Technology (NIST). 2022 · 2022
Closest in time.
Marvin Static Analyzer
Joaquín Rinaudo and Juan Heguiabehere. 2022 · 2022
Closest in time.
SOG-IS Crypto Evaluation Scheme Agreed Cryptographic Mechanisms
Senior Officials Group Information Systems Security (SOG-IS). 2022 · 2022
Closest in time.
OWASP Top 10:2021
Andrew van der Stock, Brian Glas, Neil Smithline, and Torsten Gigler. 2021 · 2022
Closest in time.
OWASP Benchmark | OWASP Foundation
Dave Wichers. 2022 · 2022
Closest in time.