A billion SMT queries a day

N Rungta - International Conference on Computer Aided …, 2022 - Springer
Abstract Amazon Web Services (AWS) is a cloud computing services provider that has made
significant investments in applying formal methods to proving correctness of its internal …

Barriers to Using Static Application Security Testing (SAST) Tools: A Literature Review

ZD Wadhams, C Izurieta, AM Reinhold - Proceedings of the 39th IEEE …, 2024 - dl.acm.org
Developers face a challenging problem with no clear solution. Modern software breaches
can wreak havoc on businesses and individuals alike. With code vulnerabilities being a …

Unhelpful assumptions in software security research

I Ryan, U Roedig, KJ Stol - Proceedings of the 2023 ACM SIGSAC …, 2023 - dl.acm.org
In the study of software security many factors must be considered. Once venturing beyond
the simplest of laboratory experiments, the researcher is obliged to contend with …

Development iterations based on web augmentation and context tasks

LG Marticorena, LA Morales, L Antonelli… - Multimedia Tools and …, 2023 - Springer
The use of prototypes in requirements engineering has widely known benefits since they
actively involve the stakeholders in the development process. Web Augmentation …

Studying Secure Coding in the Laboratory: Why, What, Where, How, and Who?

I Ryan, KJ Stol, U Roedig - 2023 IEEE/ACM 4th International …, 2023 - ieeexplore.ieee.org
Software security is an area of growing concern, with over 192,000 known vulnerabilities in
public software at the time of writing. Many aids to secure coding exist. Assessing the …

[PDF][PDF] Improving Real-World Applicability of Static Taint Analysis.

L Luo - 2021 - fb-swt.gi.de
Security breaches happen on a daily basis and are a serious threat to our society. The
average cost of a data breach in 2021 has achieved the highest record in the 17-year history …

How far are German companies in improving security through static program analysis tools?

G Piskachev, S Dziwok, T Koch… - 2022 IEEE Secure …, 2022 - ieeexplore.ieee.org
As security becomes more relevant for many com-panies, the popularity of static program
analysis (SPA) tools is increasing. In this paper, we target the use of SPA tools among …

[PDF][PDF] Secure coding in organisations: practice, culture, motivations and

I Ryan - 2024 - cora.ucc.ie
The societal consequences of insecure software are extensive. Over the past few years
ransomware attacks have caused financial and operational damage to health services [161] …

[PDF][PDF] ON IMPROVING THE ADOPTION, USABILITY, AND RETENTION OF STATIC

ZD Wadhams - 2024 - cs.montana.edu
Recent years have witnessed a surge in critical software security issues, impacting millions
of people and causing billions of dollars in damages [1]. In July of 2024, a faulty CrowdStrike …

Analysis of tools for static security testing of applications

G Leonid - 2023 - dspace.cvut.cz
This thesis presents a comprehensive evaluation of general-purpose Static Application
Security Testing (SAST) tools available to the general public and offering free versions. The …