All Stories

  1. Selecting the Data Source that Matter: Fine-Tuning Domain-Specific Ecosystem Studies with MARIN
  2. Multidimensional Research Software Categorization
  3. Total Recall? How Good Are Static Call Graphs Really?
  4. Exploring Loose Coupling of Slicing with Dynamic Symbolic Execution on the JVM
  5. Persisting and Reusing Results of Static Program Analyses on a Large Scale
  6. UPCY: Safely Updating Outdated Dependencies
  7. DGMF: Fast Generation of Comparable, Updatable Dependency Graphs for Software Repositories
  8. (Re)Use of Research Results (Is Rampant)
  9. A retrospective study of one decade of artifact evaluations
  10. What Has Artifact Evaluation Ever Done for Us?
  11. Analyzing the Direct and Transitive Impact of Vulnerabilities onto Different Artifact Repositories
  12. TaintBench: Automatic real-world malware benchmarking of Android taint analyses
  13. ModGuard : Identifying Integrity & Confidentiality Violations in Java Modules
  14. Identifying Challenges for OSS Vulnerability Scanners - A Study & Test Suite
  15. Community expectations for research artifacts and evaluation processes
  16. TACAI: an intermediate representation based on abstract interpretation
  17. PhASAR: An Inter-procedural Static Analysis Framework for C/C++
  18. CodeMatch: obfuscation won't conceal your repackaged app
  19. Hermes: assessment and creation of effective test corpora
  20. SootKeeper: runtime reusability for modular static analysis
  21. Hardening Java’s Access Control by Abolishing Implicit Privilege Elevation
  22. Call graph construction for Java libraries
  23. A vulnerability's lifetime
  24. Getting to know you: towards a capability model for Java
  25. Hidden truths in dead software paths
  26. Design your analysis: a case study on implementation reusability of data-flow functions
  27. FlowTwist: efficient context-sensitive inside-out taint analysis for large codebases
  28. A software product line for static analyses