All Stories

  1. Multidimensional Research Software Categorization
  2. Total Recall? How Good Are Static Call Graphs Really?
  3. Exploring Loose Coupling of Slicing with Dynamic Symbolic Execution on the JVM
  4. Persisting and Reusing Results of Static Program Analyses on a Large Scale
  5. UPCY: Safely Updating Outdated Dependencies
  6. DGMF: Fast Generation of Comparable, Updatable Dependency Graphs for Software Repositories
  7. (Re)Use of Research Results (Is Rampant)
  8. A retrospective study of one decade of artifact evaluations
  9. What Has Artifact Evaluation Ever Done for Us?
  10. Analyzing the Direct and Transitive Impact of Vulnerabilities onto Different Artifact Repositories
  11. TaintBench: Automatic real-world malware benchmarking of Android taint analyses
  12. ModGuard : Identifying Integrity & Confidentiality Violations in Java Modules
  13. Identifying Challenges for OSS Vulnerability Scanners - A Study & Test Suite
  14. Community expectations for research artifacts and evaluation processes
  15. TACAI: an intermediate representation based on abstract interpretation
  16. PhASAR: An Inter-procedural Static Analysis Framework for C/C++
  17. CodeMatch: obfuscation won't conceal your repackaged app
  18. Hermes: assessment and creation of effective test corpora
  19. SootKeeper: runtime reusability for modular static analysis
  20. Hardening Java’s Access Control by Abolishing Implicit Privilege Elevation
  21. Call graph construction for Java libraries
  22. A vulnerability's lifetime
  23. Getting to know you: towards a capability model for Java
  24. Hidden truths in dead software paths
  25. Design your analysis: a case study on implementation reusability of data-flow functions
  26. FlowTwist: efficient context-sensitive inside-out taint analysis for large codebases
  27. A software product line for static analyses