"False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
Fuente:
arXiv
Saved in:
| Main Authors: | Ami, Amit Seal, Moran, Kevin, Poshyvanyk, Denys, Nadkarni, Adwait |
|---|---|
| Format: | Preprint |
| Published: |
2023
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Mutation-based Evaluation of Cryptographic API Misuse Detectors
by: Ami, Amit Seal, et al.
Published: (2021)
by: Ami, Amit Seal, et al.
Published: (2021)
QASecClaw: A Multi-Agent LLM Approach for False Positive Reduction in Static Application Security Testing
by: Ameen, Mohd Ruhul, et al.
Published: (2026)
by: Ameen, Mohd Ruhul, et al.
Published: (2026)
Testing Practices, Challenges, and Developer Perspectives in Open-Source IoT Platforms
by: Rodriguez-Cardenas, Daniel, et al.
Published: (2025)
by: Rodriguez-Cardenas, Daniel, et al.
Published: (2025)
Understanding Privacy Risks in Code Models Through Training Dynamics: A Causal Approach
by: Yang, Hua, et al.
Published: (2025)
by: Yang, Hua, et al.
Published: (2025)
Many Tools, Few Exploitable Vulnerabilities: A Survey of 246 Static Code Analyzers for Security
by: Hermann, Kevin, et al.
Published: (2026)
by: Hermann, Kevin, et al.
Published: (2026)
LLM-Driven Adaptive Source-Sink Identification and False Positive Mitigation for Static Analysis
by: Lin, Shiyin
Published: (2025)
by: Lin, Shiyin
Published: (2025)
FuzzSlice: Pruning False Positives in Static Analysis Warnings Through Function-Level Fuzzing
by: Murali, Aniruddhan, et al.
Published: (2024)
by: Murali, Aniruddhan, et al.
Published: (2024)
An Extensive Comparison of Static Application Security Testing Tools
by: Esposito, Matteo, et al.
Published: (2024)
by: Esposito, Matteo, et al.
Published: (2024)
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
by: Marquer, Yoann, et al.
Published: (2026)
by: Marquer, Yoann, et al.
Published: (2026)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
How Do Semantically Equivalent Code Transformations Impact Membership Inference on LLMs for Code?
by: Yang, Hua, et al.
Published: (2025)
by: Yang, Hua, et al.
Published: (2025)
Security Testing of RESTful APIs With Test Case Mutation
by: Salva, Sebastien, et al.
Published: (2024)
by: Salva, Sebastien, et al.
Published: (2024)
Challenges in Developing Secure Software -- Results of an Interview Study in the German Software Industry
by: Mattukat, Alex R., et al.
Published: (2025)
by: Mattukat, Alex R., et al.
Published: (2025)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
by: Cusick, James J.
Published: (2025)
by: Cusick, James J.
Published: (2025)
How Secure is Secure Code Generation? Adversarial Prompts Put LLM Defenses to the Test
by: Tessa, Melissa, et al.
Published: (2026)
by: Tessa, Melissa, et al.
Published: (2026)
Towards Understanding and Applying Security Assurance Cases for Automotive Systems
by: Mohamad, Mazen
Published: (2024)
by: Mohamad, Mazen
Published: (2024)
AIM: Automated Input Set Minimization for Metamorphic Security Testing
by: Chaleshtari, Nazanin Bayati, et al.
Published: (2024)
by: Chaleshtari, Nazanin Bayati, et al.
Published: (2024)
An Exploratory Study on the Engineering of Security Features
by: Hermann, Kevin, et al.
Published: (2025)
by: Hermann, Kevin, et al.
Published: (2025)
Understanding, Implementing, and Supporting Security Assurance Cases in Safety-Critical Domains
by: Mohamad, Mazen
Published: (2025)
by: Mohamad, Mazen
Published: (2025)
An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy Perspectives
by: Guo, Hanyang, et al.
Published: (2024)
by: Guo, Hanyang, et al.
Published: (2024)
A Security Risk Assessment Method for Distributed Ledger Technology (DLT) based Applications: Three Industry Case Studies
by: Baninemeh, Elena, et al.
Published: (2024)
by: Baninemeh, Elena, et al.
Published: (2024)
Generating Proof-of-Vulnerability Tests to Help Enhance the Security of Complex Software
by: Kanchi, Shravya, et al.
Published: (2026)
by: Kanchi, Shravya, et al.
Published: (2026)
GraphQLer: Enhancing GraphQL Security with Context-Aware API Testing
by: Tsai, Omar, et al.
Published: (2025)
by: Tsai, Omar, et al.
Published: (2025)
IRIS: LLM-Assisted Static Analysis for Detecting Security Vulnerabilities
by: Li, Ziyang, et al.
Published: (2024)
by: Li, Ziyang, et al.
Published: (2024)
QLCoder: A Query Synthesizer For Static Analysis of Security Vulnerabilities
by: Wang, Claire, et al.
Published: (2025)
by: Wang, Claire, et al.
Published: (2025)
How Code Representation Shapes False-Positive Dynamics in Cross-Language LLM Vulnerability Detection
by: Chen, Maofei, et al.
Published: (2026)
by: Chen, Maofei, et al.
Published: (2026)
A Static Analysis of Popular C Packages in Linux
by: Ruohonen, Jukka, et al.
Published: (2024)
by: Ruohonen, Jukka, et al.
Published: (2024)
Toward an Android Static Analysis Approach for Data Protection
by: Khedkar, Mugdha, et al.
Published: (2024)
by: Khedkar, Mugdha, et al.
Published: (2024)
UEFI Vulnerability Signature Generation using Static and Symbolic Analysis
by: Shafiuzzaman, Md, et al.
Published: (2024)
by: Shafiuzzaman, Md, et al.
Published: (2024)
Guiding Symbolic Execution with Static Analysis and LLMs for Vulnerability Discovery
by: Shafiuzzaman, Md, et al.
Published: (2026)
by: Shafiuzzaman, Md, et al.
Published: (2026)
Can I Check What I Designed? Mapping Security Design DSLs to Code Analyzers
by: Peldszus, Sven, et al.
Published: (2026)
by: Peldszus, Sven, et al.
Published: (2026)
A Taxonomy of Functional Security Features and How They Can Be Located
by: Hermann, Kevin, et al.
Published: (2025)
by: Hermann, Kevin, et al.
Published: (2025)
DITING: A Static Analyzer for Identifying Bad Partitioning Issues in TEE Applications
by: Ma, Chengyan, et al.
Published: (2025)
by: Ma, Chengyan, et al.
Published: (2025)
CrossInspector: A Static Analysis Approach for Cross-Contract Vulnerability Detection
by: Chen, Xiao
Published: (2024)
by: Chen, Xiao
Published: (2024)
Static Semantics Reconstruction for Enhancing JavaScript-WebAssembly Multilingual Malware Detection
by: Xia, Yifan, et al.
Published: (2023)
by: Xia, Yifan, et al.
Published: (2023)
SCRIBE: Practical Static Binary Patching via Binary-Aware Recompilation of Decompiled Code
by: Dai, Han, et al.
Published: (2026)
by: Dai, Han, et al.
Published: (2026)
A Context-Sensitive, Outlier-Based Static Analysis to Find Kernel Race Conditions
by: Dossche, Niels, et al.
Published: (2024)
by: Dossche, Niels, et al.
Published: (2024)
LibScan: Smart Contract Library Misuse Detection with Iterative Feedback and Static Verification
by: Wang, Yishun, et al.
Published: (2026)
by: Wang, Yishun, et al.
Published: (2026)
Security study based on the Chatgptplugin system: ldentifying Security Vulnerabilities
by: Ren, Ruomai
Published: (2025)
by: Ren, Ruomai
Published: (2025)
Leveraging Security Observability to Strengthen Security of Digital Ecosystem Architecture
by: Ramachandran, Renjith
Published: (2024)
by: Ramachandran, Renjith
Published: (2024)
Similar Items
-
Mutation-based Evaluation of Cryptographic API Misuse Detectors
by: Ami, Amit Seal, et al.
Published: (2021) -
QASecClaw: A Multi-Agent LLM Approach for False Positive Reduction in Static Application Security Testing
by: Ameen, Mohd Ruhul, et al.
Published: (2026) -
Testing Practices, Challenges, and Developer Perspectives in Open-Source IoT Platforms
by: Rodriguez-Cardenas, Daniel, et al.
Published: (2025) -
Understanding Privacy Risks in Code Models Through Training Dynamics: A Causal Approach
by: Yang, Hua, et al.
Published: (2025) -
Many Tools, Few Exploitable Vulnerabilities: A Survey of 246 Static Code Analyzers for Security
by: Hermann, Kevin, et al.
Published: (2026)