{"id":"https://openalex.org/W3216469410","doi":"https://doi.org/10.1109/iri51335.2021.00025","title":"Foraging-Theoretic Tool Composition: An Empirical Study on Vulnerability Discovery","display_name":"Foraging-Theoretic Tool Composition: An Empirical Study on Vulnerability Discovery","publication_year":2021,"publication_date":"2021-08-01","ids":{"openalex":"https://openalex.org/W3216469410","doi":"https://doi.org/10.1109/iri51335.2021.00025","mag":"3216469410"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/iri51335.2021.00025","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5033845556","display_name":"Mona Assarandarban","orcid":null},"institutions":[{"id":"https://openalex.org/I63135867","display_name":"University of Cincinnati","ror":"https://ror.org/01e3m7079","country_code":"US","type":"funder","lineage":["https://openalex.org/I63135867"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mona Assarandarban","raw_affiliation_strings":["University of Cincinnati, Cincinnati, OH, USA"],"affiliations":[{"raw_affiliation_string":"University of Cincinnati, Cincinnati, OH, USA","institution_ids":["https://openalex.org/I63135867"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058240042","display_name":"Tanmay Bhowmik","orcid":"https://orcid.org/0000-0002-0456-161X"},"institutions":[{"id":"https://openalex.org/I99041443","display_name":"Mississippi State University","ror":"https://ror.org/0432jq872","country_code":"US","type":"funder","lineage":["https://openalex.org/I4210141039","https://openalex.org/I99041443"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tanmay Bhowmik","raw_affiliation_strings":["Mississippi State University, Mississippi State, MS, USA"],"affiliations":[{"raw_affiliation_string":"Mississippi State University, Mississippi State, MS, USA","institution_ids":["https://openalex.org/I99041443"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5110818628","display_name":"Anh Quoc","orcid":null},"institutions":[{"id":"https://openalex.org/I99041443","display_name":"Mississippi State University","ror":"https://ror.org/0432jq872","country_code":"US","type":"funder","lineage":["https://openalex.org/I4210141039","https://openalex.org/I99041443"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Anh Quoc Do","raw_affiliation_strings":["Mississippi State University, Mississippi State, MS, USA"],"affiliations":[{"raw_affiliation_string":"Mississippi State University, Mississippi State, MS, USA","institution_ids":["https://openalex.org/I99041443"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056471995","display_name":"Surendra Raju Chekuri","orcid":null},"institutions":[{"id":"https://openalex.org/I99041443","display_name":"Mississippi State University","ror":"https://ror.org/0432jq872","country_code":"US","type":"funder","lineage":["https://openalex.org/I4210141039","https://openalex.org/I99041443"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Surendra Chekuri","raw_affiliation_strings":["Mississippi State University, Mississippi State, MS, USA"],"affiliations":[{"raw_affiliation_string":"Mississippi State University, Mississippi State, MS, USA","institution_ids":["https://openalex.org/I99041443"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101993851","display_name":"Wentao Wang","orcid":"https://orcid.org/0000-0003-3548-3068"},"institutions":[{"id":"https://openalex.org/I1342911587","display_name":"Oracle (United States)","ror":"https://ror.org/006c77m33","country_code":"US","type":"funder","lineage":["https://openalex.org/I1342911587"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Wentao Wang","raw_affiliation_strings":["Oracle, Seattle, WA, USA"],"affiliations":[{"raw_affiliation_string":"Oracle, Seattle, WA, USA","institution_ids":["https://openalex.org/I1342911587"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5044324103","display_name":"Nan Niu","orcid":"https://orcid.org/0000-0001-5566-2368"},"institutions":[{"id":"https://openalex.org/I63135867","display_name":"University of Cincinnati","ror":"https://ror.org/01e3m7079","country_code":"US","type":"funder","lineage":["https://openalex.org/I63135867"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Nan Niu","raw_affiliation_strings":["University of Cincinnati, Cincinnati, OH, USA"],"affiliations":[{"raw_affiliation_string":"University of Cincinnati, Cincinnati, OH, USA","institution_ids":["https://openalex.org/I63135867"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":56},"biblio":{"volume":null,"issue":null,"first_page":"139","last_page":"146"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9997,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9994,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability","score":0.63687485},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.51607484},{"id":"https://openalex.org/keywords/empirical-research","display_name":"Empirical Research","score":0.47368148}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7586292},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.6628267},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.63687485},{"id":"https://openalex.org/C165287380","wikidata":"https://www.wikidata.org/wiki/Q2916569","display_name":"Foraging","level":2,"score":0.54228646},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.5266219},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.51607484},{"id":"https://openalex.org/C120936955","wikidata":"https://www.wikidata.org/wiki/Q2155640","display_name":"Empirical research","level":2,"score":0.47368148},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.4722989},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.41260087},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2203775},{"id":"https://openalex.org/C201995342","wikidata":"https://www.wikidata.org/wiki/Q682496","display_name":"Systems engineering","level":1,"score":0.11504662},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.11388925},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.096821964},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.081903964},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/iri51335.2021.00025","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":33,"referenced_works":["https://openalex.org/W1507165380","https://openalex.org/W1748815599","https://openalex.org/W1974868382","https://openalex.org/W1999898351","https://openalex.org/W2017747296","https://openalex.org/W2041817886","https://openalex.org/W2044049174","https://openalex.org/W2085925880","https://openalex.org/W2097662691","https://openalex.org/W2119871945","https://openalex.org/W2130758759","https://openalex.org/W2132276070","https://openalex.org/W2151996389","https://openalex.org/W2160570190","https://openalex.org/W2316276308","https://openalex.org/W2329112369","https://openalex.org/W2401973021","https://openalex.org/W2546851909","https://openalex.org/W2547944011","https://openalex.org/W2552196466","https://openalex.org/W2560091861","https://openalex.org/W2560147852","https://openalex.org/W2614421426","https://openalex.org/W2770055223","https://openalex.org/W2896647264","https://openalex.org/W2898102886","https://openalex.org/W2909837460","https://openalex.org/W2992475184","https://openalex.org/W3036033449","https://openalex.org/W3086501235","https://openalex.org/W3140745842","https://openalex.org/W4239336087","https://openalex.org/W4292862031"],"related_works":["https://openalex.org/W4200081355","https://openalex.org/W3081944365","https://openalex.org/W301102721","https://openalex.org/W2890381285","https://openalex.org/W2294784349","https://openalex.org/W2136432055","https://openalex.org/W2135179174","https://openalex.org/W2048910501","https://openalex.org/W1979659965","https://openalex.org/W1932300341"],"abstract_inverted_index":{"Discovering":[0],"vulnerabilities":[1],"is":[2,23,50,73],"an":[3],"information-intensive":[4],"task":[5,22],"that":[6,17],"requires":[7],"a":[8,57,98,105,114,135],"developer":[9],"to":[10,26,43,61,138],"locate":[11],"the":[12,15,27,45,65,81,88,122,140],"defects":[13],"in":[14,113,151],"code":[16,29],"have":[18,40],"security":[19,36],"implications.":[20],"The":[21],"difficult":[24],"due":[25],"growing":[28],"complexity":[30],"and":[31,102,124,133],"some":[32],"developer's":[33],"lack":[34],"of":[35,59,87,126],"expertise.":[37],"Although":[38],"tools":[39,60,70],"been":[41],"created":[42],"ease":[44],"difficulty,":[46],"no":[47],"single":[48],"one":[49],"sufficient.":[51],"In":[52,76],"practice,":[53],"developers":[54],"often":[55],"use":[56],"combination":[58],"uncover":[62],"vulnerabilities.":[63,154],"Yet,":[64],"basis":[66],"on":[67],"which":[68],"different":[69],"are":[71],"composed":[72],"under":[74],"explored.":[75],"this":[77],"paper,":[78],"we":[79],"examine":[80],"composition":[82,131],"base":[83],"by":[84,93],"taking":[85],"advantage":[86],"tool":[89,149],"design":[90,99],"patterns":[91,112],"informed":[92],"foraging":[94,127],"theory.":[95],"We":[96],"follow":[97],"science":[100],"methodology":[101],"carry":[103],"out":[104],"three-step":[106],"empirical":[107],"study:":[108],"mapping":[109],"34":[110],"foraging-theoretic":[111],"specific":[115],"vulnerability":[116],"discovery":[117],"tool,":[118],"formulating":[119],"hypotheses":[120],"about":[121],"value":[123],"cost":[125],"when":[128],"considering":[129],"two":[130],"scenarios,":[132],"performing":[134],"human-subject":[136],"study":[137],"test":[139],"hypotheses.":[141],"Our":[142],"work":[143],"offers":[144],"insights":[145],"into":[146],"guiding":[147],"developers'":[148],"usage":[150],"detecting":[152],"software":[153]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W3216469410","counts_by_year":[],"updated_date":"2025-03-28T18:43:17.004100","created_date":"2021-12-06"}