{"id":"https://openalex.org/W2137726309","doi":"https://doi.org/10.1145/1029894.1029911","title":"Testing static analysis tools using exploitable buffer overflows from open source code","display_name":"Testing static analysis tools using exploitable buffer overflows from open source code","publication_year":2004,"publication_date":"2004-10-31","ids":{"openalex":"https://openalex.org/W2137726309","doi":"https://doi.org/10.1145/1029894.1029911","mag":"2137726309"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/1029894.1029911","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5060054034","display_name":"Misha Zitser","orcid":null},"institutions":[{"id":"https://openalex.org/I2799548008","display_name":"D. E. Shaw Research","ror":"https://ror.org/02s04h872","country_code":"US","type":"company","lineage":["https://openalex.org/I2799548008"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Misha Zitser","raw_affiliation_strings":["D. E. Shaw Group"],"affiliations":[{"raw_affiliation_string":"D. E. Shaw Group","institution_ids":["https://openalex.org/I2799548008"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043314383","display_name":"Richard P. Lippmann","orcid":null},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Richard Lippmann","raw_affiliation_strings":["MIT Lincoln Laboratory;"],"affiliations":[{"raw_affiliation_string":"MIT Lincoln Laboratory;","institution_ids":["https://openalex.org/I63966007"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5109834810","display_name":"Tim Leek","orcid":null},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tim Leek","raw_affiliation_strings":["MIT Lincoln Laboratory;"],"affiliations":[{"raw_affiliation_string":"MIT Lincoln Laboratory;","institution_ids":["https://openalex.org/I63966007"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":13.073,"has_fulltext":false,"cited_by_count":223,"citation_normalized_percentile":{"value":0.963979,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"97","last_page":"106"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9995,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9995,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11005","display_name":"Radiation Effects in Electronics","score":0.9973,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12423","display_name":"Software Reliability and Analysis Research","score":0.9966,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/buffer-overflow","display_name":"Buffer overflow","score":0.93617535},{"id":"https://openalex.org/keywords/heap","display_name":"Heap (data structure)","score":0.7376287},{"id":"https://openalex.org/keywords/buffer","display_name":"Buffer (optical fiber)","score":0.61812717},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.5714906},{"id":"https://openalex.org/keywords/subroutine","display_name":"Subroutine","score":0.4146338}],"concepts":[{"id":"https://openalex.org/C40842320","wikidata":"https://www.wikidata.org/wiki/Q19423","display_name":"Buffer overflow","level":2,"score":0.93617535},{"id":"https://openalex.org/C134757568","wikidata":"https://www.wikidata.org/wiki/Q274089","display_name":"Heap (data structure)","level":2,"score":0.7376287},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7283609},{"id":"https://openalex.org/C145018004","wikidata":"https://www.wikidata.org/wiki/Q4985944","display_name":"Buffer (optical fiber)","level":2,"score":0.61812717},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.5714906},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.5521306},{"id":"https://openalex.org/C3018397939","wikidata":"https://www.wikidata.org/wiki/Q3644502","display_name":"Open source","level":3,"score":0.51068455},{"id":"https://openalex.org/C97686452","wikidata":"https://www.wikidata.org/wiki/Q7604153","display_name":"Static analysis","level":2,"score":0.4656518},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.46290195},{"id":"https://openalex.org/C96147967","wikidata":"https://www.wikidata.org/wiki/Q190686","display_name":"Subroutine","level":2,"score":0.4146338},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.3717721},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.19628072},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.074976355},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/1029894.1029911","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":21,"referenced_works":["https://openalex.org/W132371169","https://openalex.org/W1525451871","https://openalex.org/W1535713556","https://openalex.org/W1579850852","https://openalex.org/W1655226010","https://openalex.org/W1839576640","https://openalex.org/W193709894","https://openalex.org/W2019448108","https://openalex.org/W2097697841","https://openalex.org/W2097990218","https://openalex.org/W2102440514","https://openalex.org/W2103714221","https://openalex.org/W2137952932","https://openalex.org/W2138538192","https://openalex.org/W2146455667","https://openalex.org/W2167231283","https://openalex.org/W2611598995","https://openalex.org/W3174107850","https://openalex.org/W4232822984","https://openalex.org/W4253641612","https://openalex.org/W60370665"],"related_works":["https://openalex.org/W3126155085","https://openalex.org/W3022539710","https://openalex.org/W2960453428","https://openalex.org/W2388448064","https://openalex.org/W2368842303","https://openalex.org/W2136651729","https://openalex.org/W2051021283","https://openalex.org/W2002128171","https://openalex.org/W1981237417","https://openalex.org/W1649260624"],"abstract_inverted_index":{"Five":[0],"modern":[1],"static":[2],"analysis":[3],"tools":[4,122],"(ARCHER,":[5],"BOON,":[6],"Poly-Space":[7,90],"C":[8],"Verifier,":[9],"Splint,":[10],"and":[11,32,42,52,57,62,70,72,78,91,100,110,135,145],"UNO)":[12],"were":[13,86,108],"evaluated":[14],"using":[15,67],"source":[16,133],"code":[17,35,134],"examples":[18,85],"containing":[19],"14":[20],"exploitable":[21],"buffer":[22,47,64,76],"overflow":[23],"vulnerabilities":[24],"found":[25],"in":[26],"various":[27],"versions":[28],"of":[29,98,132],"Sendmail,":[30],"BIND,":[31],"WU-FTPD.":[33],"Each":[34],"example":[36],"included":[37,53],"a":[38,43],"\"BAD\"":[39,84],"case":[40,45],"with":[41],"\"OK\"":[44],"without":[46],"overflows.":[48],"Buffer":[49],"overflows":[50],"varied":[51],"stack,":[54],"heap,":[55],"bss":[56],"data":[58],"buffers;":[59],"access":[60,66],"above":[61],"below":[63],"bounds;":[65],"pointers,":[68],"indices,":[69],"functions;":[71],"scope":[73],"differences":[74],"between":[75,143],"creation":[77],"use.":[79],"Detection":[80],"rates":[81,97,107],"for":[82,89,113,126],"the":[83],"low":[87],"except":[88],"Splint":[92],"which":[93],"had":[94],"average":[95,104],"detection":[96],"87%":[99],"57%,":[101],"respectively.":[102],"However,":[103],"false":[105],"alarm":[106],"high":[109],"roughly":[111],"50%":[112],"these":[114,120],"two":[115,121],"tools.":[116],"On":[117],"patched":[118,146],"programs":[119],"produce":[123],"one":[124],"warning":[125],"every":[127],"12":[128],"to":[129,140],"46":[130],"lines":[131],"neither":[136],"tool":[137],"appears":[138],"able":[139],"accurately":[141],"distinguished":[142],"vulnerable":[144],"code.":[147]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2137726309","counts_by_year":[{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":6},{"year":2021,"cited_by_count":5},{"year":2020,"cited_by_count":5},{"year":2019,"cited_by_count":10},{"year":2018,"cited_by_count":8},{"year":2017,"cited_by_count":9},{"year":2016,"cited_by_count":9},{"year":2015,"cited_by_count":9},{"year":2014,"cited_by_count":14},{"year":2013,"cited_by_count":12},{"year":2012,"cited_by_count":19}],"updated_date":"2025-01-19T21:32:20.852730","created_date":"2016-06-24"}