Fetching the paper…
Reading the bibliography…
Security Application Programming Interfaces (APIs) are crucial for ensuring software security.
Symbolic execution and program testing
James C King · 1976
Earlier work this paper cites.
How to predict congruential generators
Hugo Krawczyk · 1992
Earlier work this paper cites.
Evidence-based software engineering
Barbara A Kitchenham, Tore Dyba, and Magne Jorgensen · 2004
Earlier work this paper cites.
A brief survey of program slicing
Baowen Xu, Ju Qian, Xiaofang Zhang, Zhongqiang Wu, and Lin Chen · 2005
Earlier work this paper cites.
Using thematic analysis in psychology
Virginia Braun and Victoria Clarke · 2006
Earlier work this paper cites.
Guidelines for performing systematic literature reviews in software engineering
B. Kitchenham and S. Charters · 2007
Earlier work this paper cites.
Recommendation for key management part 3: Application-specific key management guidance
Elaine Barker, William Burr, Alicia Jones, Timothy Polk, Scott Rose, Miles Smid, Quynh Dang, et al · 2009
Earlier work this paper cites.
Prohibiting secure sockets layer (SSL) version 2.0
Sean Turner and Tim Polk · 2011
Earlier work this paper cites.
The Soot framework for Java program analysis: a retrospective
Patrick Lam, Eric Bodden, Ondrej Lhoták, and Laurie Hendren · 2011
Earlier work this paper cites.
The most dangerous code in the world: validating SSL certificates in non-browser software
Martin Georgiev, Subodh Iyengar, Suman Jana, Rishita Anubhai, Dan Boneh, and Vitaly Shmatikov · 2012
Earlier work this paper cites.
RFC 6749: The OAuth 2.0 authorization framework, 2012
Dick Hardt · 2012
Earlier work this paper cites.
An empirical study of cryptographic misuse in android applications
Manuel Egele, David Brumley, Yanick Fratantonio, and Christopher Kruegel · 2013
Earlier work this paper cites.
Management of information security
Michael E Whitman and Herbert J Mattord · 2013
Earlier work this paper cites.
Factoring rsa keys from certified smart cards: Coppersmith in the wild
Daniel J Bernstein, Yun-An Chang, Chen-Mou Cheng, Li-Ping Chou, Nadia Heninger, Tanja Lange, and Nicko Van Someren · 2013
Earlier work this paper cites.
Guidelines for snowballing in systematic literature studies and a replication in software engineering
Claes Wohlin · 2014
Earlier work this paper cites.
OpenID Connect core 1.0 incorporating errata set 1, 2014
Nat Sakimura, John Bradley, Mike Jones, Breno de Medeiros, and Chuck Mortimore · 2014
Earlier work this paper cites.
Flowdroid: Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for Android apps
Steven Arzt, Siegfried Rasthofer, Christian Fritz, Eric Bodden, Alexandre Bartel, Jacques Klein, Yves Le Traon, Damien Octeau, and Patrick McDaniel · 2014
Earlier work this paper cites.
More guidelines than rules: CSRF vulnerabilities from noncompliant OAuth 2.0 implementations
Ethan Shernan, Henry Carter, Dave Tian, Patrick Traynor, and Kevin Butler · 2015
Earlier work this paper cites.
Deprecating secure sockets layer version 3.0, 2015
Richard Barnes, Martin Thomson, Alfredo Pironti, and Adam Langley · 2015
Earlier work this paper cites.
Proof key for code exchange by OAuth public clients
Nat Sakimura, John Bradley, and Naveen Agarwal · 2015
Earlier work this paper cites.
Developers are not the enemy!: The need for usable security APIs
Matthew Green and Matthew Smith · 2016
Earlier work this paper cites.
Towards the usability evaluation of security APIs
Peter Leo Gorski and Luigi Lo Iacono · 2016
Earlier work this paper cites.
Androzoo: Collecting millions of Android apps for the research community
Kevin Allix, Tegawendé F Bissyandé, Jacques Klein, and Yves Le Traon · 2016
Earlier work this paper cites.
Nist special publication 800-57 part 1, revision 4
Elaine Barker and Quynh Dang · 2016
Earlier work this paper cites.
MUBench: A benchmark for API-misuse detectors
Sven Amann, Sarah Nadi, Hoan A Nguyen, Tien N Nguyen, and Mira Mezini · 2016
Earlier work this paper cites.
Stack Overflow considered harmful? the impact of copy&paste on Android application security
Felix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky, Yasemin Acar, Michael Backes, and Sascha Fahl · 2017
Earlier work this paper cites.
RFC 8018: PKCS# 5: Password-based cryptography specification version 2.1, 2017
Burt Kaliski and A Rusch · 2017
Earlier work this paper cites.
Yarik markov, alex petit bianco, and clement baisse. announcing the first sha1 collision
Marc Stevens, Elie Bursztein, Pierre Karpman, and Ange Albertini · 2017
Earlier work this paper cites.
Practical evaluation of static analysis tools for cryptography: Benchmarking method and case study
Alexandre Braga, Ricardo Dahab, Nuno Antunes, Nuno Laranjeiro, and Marco Vieira · 2017
Cited alongside, same era.
Collusive data leak and more: Large-scale threat analysis of inter-app communications
Amiangshu Bosu, Fang Liu, Danfeng Yao, and Gang Wang · 2017
Cited alongside, same era.
Broken Fingers: On the Usage of the Fingerprint API in Android
Antonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel, Giovanni Vigna, Simon Pak Ho Chung, and Wenke Lee · 2018
Cited alongside, same era.
GDPR: General Data Protection Regulation (EU) 2016/679: Post-reform Personal Data Protection in the European Union
Mariusz Krzysztofek · 2018
Cited alongside, same era.
Security in the software development lifecycle
Hala Assal and Sonia Chiasson · 2018
Cited alongside, same era.
Online Appendix of "Detecting Misuses of Security APIs: A Systematic Review", 2023
Z. Mousavi, C. Islam, M. A. Babar, A. Abuadbba, and K. Moore · 2023
Closest in time.
Pypl popularity of programming language, 2023
Pierre Carbonnelle · 2023
Closest in time.
New in Android samples: Authenticating to remote servers using the fingerprint API, 2015
Google · 2023
Closest in time.
Local authentication on Android, 2017
OWASP-MASTG · 2023
Closest in time.
Yubikeys, 2017
YubiCo · 2023
Closest in time.
Spring security
Spring · 2023
Closest in time.
SafetyNet Attestation API, 2020
Google · 2023
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Na Meng, Stefan Nagy, Danfeng Yao, Wenjie Zhuang, and Gustavo Arango Argoty · 2018
Cited alongside, same era.
Finding clues for your secrets: Semantics-driven
Yuhong Nan, Zhemin Yang, Xiaofeng Wang, Yuan Zhang, Donglai Zhu, and Min Yang · 2018
Cited alongside, same era.
Cryptoguard: High precision detection of cryptographic vulnerabilities in massive-sized java projects
Sazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon, Ke Tian, Miles Frantz, Murat Kantarcioglu, and Danfeng Yao · 2019
Cited alongside, same era.
Oauthlint: An empirical study on oauth bugs in android applications
Tamjid Al Rahat, Yu Feng, and Yuan Tian · 2019
Cited alongside, same era.
CrySL: An extensible approach to validating the correct usage of cryptographic APIs
Stefan Krüger, Johannes Späth, Karim Ali, Eric Bodden, and Mira Mezini · 2019
Cited alongside, same era.
The impact of developer experience in using Java cryptography
Mohammadreza Hazhirpasand, Mohammad Ghafari, Stefan Krüger, Eric Bodden, and Oscar Nierstrasz · 2019
Cited alongside, same era.
Stack Overflow considered helpful! deep learning security nudges towards stronger cryptography
Felix Fischer, Huang Xiao, Ching-Yu Kao, Yannick Stachelscheid, Benjamin Johnson, Danial Razar, Paul Fawkesley, Nat Buckley, Konstantin Böttinger, Paul Muntean, et al · 2019
Cited alongside, same era.
Closest in time.
Jdk 19 documentation, 2022
Oracle · 2023
Closest in time.
Deprecating TLSv1.0 and TLSv1., 2021
K. Moriarty and S. Farrell · 2023
Closest in time.
CWE-306: Missing Authentication for Critical Function, a
Common Weakness Enumeration · 2023
Closest in time.
CWE-862: Missing authorization, b
Common Weakness Enumeration · 2023
Closest in time.
CWE-863: Incorrect authorization, c
Common Weakness Enumeration · 2023
Closest in time.
Apktool - a tool for reverse engineering Android apk files, 2010
Tumbleson Connor and Wiśniewski Ryszard · 2023
Closest in time.
Reverse engineering and pentesting for Android applications, 2012
Anthony Desnos · 2023
Closest in time.
Watson libraries for analysis WALA
IBM: T.J · 2023
Closest in time.
Large language models for software engineering: A systematic literature review
Xinyi Hou, Yanjie Zhao, Yue Liu, Zhou Yang, Kailong Wang, Li Li, Xiapu Luo, David Lo, John Grundy, and Haoyu Wang · 2023
Closest in time.
The programmer’s assistant: Conversational interaction with a large language model for software development
Steven I Ross, Fernando Martinez, Stephanie Houde, Michael Muller, and Justin D Weisz · 2023
Closest in time.
Automated program repair in the era of large pre-trained language models
Chunqiu Steven Xia, Yuxiang Wei, and Lingming Zhang · 2023
Closest in time.
Biometrics api, a
Google · 2023
Closest in time.
Play integrity, b
Google · 2023
Closest in time.
Hipaa (health insurance portability and accountability act)
U.S. Department of Health & Human Services · 2024
Closest in time.
A multi-vocal literature review on challenges and critical success factors of phishing education, training and awareness
Orvila Sarker, Asangi Jayatilaka, Sherif Haggag, Chelsea Liu, and M Ali Babar · 2024
Closest in time.
Demystifying and detecting misuses of deep learning apis
Moshi Wei, Nima Shiri Harzevili, YueKai Huang, Jinqiu Yang, Junjie Wang, and Song Wang · 2024
Closest in time.
Using an llm to help with code understanding
Daye Nam, Andrew Macvean, Vincent Hellendoorn, Bogdan Vasilescu, and Brad Myers · 2024
Closest in time.
An investigation into misuse of Java security APIs by large language models
Zahra Mousavi, Chadni Islam, Kristen Moore, Alsharif Abuadbba, and M Ali Babar · 2024
Closest in time.
Compiler-directed migrating api callsite of client code
Hao Zhong and Na Meng · 2024
Closest in time.
Virtual reality and gamification in education: a systematic review
Georgios Lampropoulos et al · 2024
Closest in time.