{"id":"https://openalex.org/W4389544206","doi":"https://doi.org/10.1109/icsme58846.2023.00060","title":"Finding an Optimal Set of Static Analyzers To Detect Software Vulnerabilities","display_name":"Finding an Optimal Set of Static Analyzers To Detect Software Vulnerabilities","publication_year":2023,"publication_date":"2023-10-01","ids":{"openalex":"https://openalex.org/W4389544206","doi":"https://doi.org/10.1109/icsme58846.2023.00060"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/icsme58846.2023.00060","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101981290","display_name":"Jiaqi He","orcid":"https://orcid.org/0000-0002-0343-3712"},"institutions":[{"id":"https://openalex.org/I154425047","display_name":"University of Alberta","ror":"https://ror.org/0160cpw27","country_code":"CA","type":"education","lineage":["https://openalex.org/I154425047"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Jiaqi He","raw_affiliation_strings":["University of Alberta"],"affiliations":[{"raw_affiliation_string":"University of Alberta","institution_ids":["https://openalex.org/I154425047"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068861645","display_name":"Revan MacQueen","orcid":null},"institutions":[{"id":"https://openalex.org/I154425047","display_name":"University of Alberta","ror":"https://ror.org/0160cpw27","country_code":"CA","type":"education","lineage":["https://openalex.org/I154425047"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Revan MacQueen","raw_affiliation_strings":["University of Alberta"],"affiliations":[{"raw_affiliation_string":"University of Alberta","institution_ids":["https://openalex.org/I154425047"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087262925","display_name":"Natalie Bombardieri","orcid":null},"institutions":[{"id":"https://openalex.org/I154425047","display_name":"University of Alberta","ror":"https://ror.org/0160cpw27","country_code":"CA","type":"education","lineage":["https://openalex.org/I154425047"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Natalie Bombardieri","raw_affiliation_strings":["University of Alberta"],"affiliations":[{"raw_affiliation_string":"University of Alberta","institution_ids":["https://openalex.org/I154425047"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5038781215","display_name":"Karim Ali","orcid":"https://orcid.org/0000-0002-5516-1376"},"institutions":[{"id":"https://openalex.org/I154425047","display_name":"University of Alberta","ror":"https://ror.org/0160cpw27","country_code":"CA","type":"education","lineage":["https://openalex.org/I154425047"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Karim Ali","raw_affiliation_strings":["University of Alberta"],"affiliations":[{"raw_affiliation_string":"University of Alberta","institution_ids":["https://openalex.org/I154425047"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103266506","display_name":"James R. Wright","orcid":"https://orcid.org/0000-0001-9622-5842"},"institutions":[{"id":"https://openalex.org/I154425047","display_name":"University of Alberta","ror":"https://ror.org/0160cpw27","country_code":"CA","type":"education","lineage":["https://openalex.org/I154425047"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"James R. Wright","raw_affiliation_strings":["University of Alberta"],"affiliations":[{"raw_affiliation_string":"University of Alberta","institution_ids":["https://openalex.org/I154425047"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5110303479","display_name":"Cristina Cifuentes","orcid":null},"institutions":[{"id":"https://openalex.org/I1342911587","display_name":"Oracle (United States)","ror":"https://ror.org/006c77m33","country_code":"US","type":"company","lineage":["https://openalex.org/I1342911587"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Cristina Cifuentes","raw_affiliation_strings":["Oracle"],"affiliations":[{"raw_affiliation_string":"Oracle","institution_ids":["https://openalex.org/I1342911587"]}]}],"institution_assertions":[],"countries_distinct_count":2,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":67},"biblio":{"volume":null,"issue":null,"first_page":"463","last_page":"473"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9997,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9997,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9997,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12423","display_name":"Software Reliability and Analysis Research","score":0.9996,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability","score":0.59622127}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8487414},{"id":"https://openalex.org/C55166926","wikidata":"https://www.wikidata.org/wiki/Q2892946","display_name":"Oracle","level":2,"score":0.7354177},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.6381641},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.59622127},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.5895567},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.516237},{"id":"https://openalex.org/C97686452","wikidata":"https://www.wikidata.org/wiki/Q7604153","display_name":"Static analysis","level":2,"score":0.50765574},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.32097366},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.16549301},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.14152536},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.08612904}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/icsme58846.2023.00060","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/10","score":0.5,"display_name":"Reduced inequalities"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":19,"referenced_works":["https://openalex.org/W1128523153","https://openalex.org/W145844368","https://openalex.org/W1575764074","https://openalex.org/W2032074358","https://openalex.org/W2077715947","https://openalex.org/W2097697841","https://openalex.org/W2129749009","https://openalex.org/W2146455667","https://openalex.org/W2165729504","https://openalex.org/W2170612356","https://openalex.org/W2293239441","https://openalex.org/W2402601480","https://openalex.org/W2514084604","https://openalex.org/W2877214426","https://openalex.org/W2990491324","https://openalex.org/W3018689464","https://openalex.org/W4254666025","https://openalex.org/W586722081","https://openalex.org/W69361866"],"related_works":["https://openalex.org/W4293864700","https://openalex.org/W4233149903","https://openalex.org/W3110702597","https://openalex.org/W2524540579","https://openalex.org/W2326878701","https://openalex.org/W2125620709","https://openalex.org/W2110441383","https://openalex.org/W2078761926","https://openalex.org/W2073713056","https://openalex.org/W1498872724"],"abstract_inverted_index":{"Software":[0],"vulnerabilities":[1,8,25,107],"are":[2],"ubiquitous":[3],"and":[4,21,94,124],"costly.":[5],"To":[6,63],"detect":[7],"earlier":[9],"during":[10],"development,":[11],"organizations":[12,40,95],"deploy":[13],"a":[14,44,73,97,137,148,155,159,172],"set":[15,55,138],"of":[16,35,46,60,83,139,158],"static":[17,85,120],"analyzers":[18,49,121,145],"to":[19,31,109,151],"locate":[20],"eventually":[22],"fix":[23],"these":[24,65],"before":[26],"releasing":[27],"their":[28,51,110],"software.":[29],"Due":[30],"the":[32,89,152],"prohibitive":[33],"cost":[34],"running":[36],"all":[37,47],"available":[38,84],"analyzers,":[39],"must":[41],"run":[42],"only":[43],"subset":[45],"possible":[48],"on":[50,105],"codebases.":[52],"Choosing":[53],"this":[54],"deterministically":[56],"leaves":[57],"recognizable":[58],"gaps":[59],"vulnerability":[61,130],"coverage.":[62],"overcome":[64],"challenges,":[66],"we":[67,132,164],"present":[68],"Randomized":[69],"Best":[70],"Response":[71],"(RBR),":[72],"method":[74],"that":[75,134,146],"computes":[76],"an":[77],"optimal":[78],"randomization":[79],"over":[80],"size-bounded":[81],"sets":[82],"analyzers.":[86],"RBR":[87,135,167],"models":[88],"relationship":[90],"between":[91],"malicious":[92,116],"users":[93],"as":[96],"leader-follower":[98],"Stackelberg":[99],"security":[100,111],"game.":[101],"Our":[102],"solution":[103],"focuses":[104],"software":[106],"due":[108],"implications":[112],"when":[113],"exploited":[114],"by":[115,142],"users.":[117],"Using":[118],"8":[119,125],"for":[122],"C/C++":[123],"Common":[126],"Weakness":[127],"Enumeration":[128],"(CWE)":[129],"types,":[131],"show":[133,165],"outperforms":[136],"natural":[140],"baselines":[141],"always":[143],"picking":[144],"achieve":[147],"higher":[149],"benefit":[150],"defender.":[153],"Through":[154],"case":[156],"study":[157],"large":[160],"system":[161],"at":[162],"Oracle,":[163],"how":[166],"may":[168],"be":[169],"used":[170],"in":[171],"real-world":[173],"scenario.":[174]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4389544206","counts_by_year":[],"updated_date":"2025-01-07T07:31:52.418447","created_date":"2023-12-12"}