AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts
Fuente:
arXiv
Salvato in:
| Autori principali: | Basak, Setu Kumar, English, K. Virgil, Ogura, Ken, Kambara, Vitesh, Reaves, Bradley, Williams, Laurie |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2024
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
RiskHarvester: A Risk-based Tool to Prioritize Secret Removal Efforts in Software Artifacts
di: Basak, Setu Kumar, et al.
Pubblicazione: (2025)
di: Basak, Setu Kumar, et al.
Pubblicazione: (2025)
Asset-centric Threat Modeling for AI-based Systems
di: von der Assen, Jan, et al.
Pubblicazione: (2024)
di: von der Assen, Jan, et al.
Pubblicazione: (2024)
Attackers reveal their arsenal: An investigation of adversarial techniques in CTI reports
di: Rahman, Md Rayhanur, et al.
Pubblicazione: (2024)
di: Rahman, Md Rayhanur, et al.
Pubblicazione: (2024)
Verifiable Provenance of Software Artifacts with Zero-Knowledge Compilation
di: Ron, Javier, et al.
Pubblicazione: (2026)
di: Ron, Javier, et al.
Pubblicazione: (2026)
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
di: Seth, Aishwarya, et al.
Pubblicazione: (2023)
di: Seth, Aishwarya, et al.
Pubblicazione: (2023)
OmniBOR: A System for Automatic, Verifiable Artifact Resolution across Software Supply Chains
di: Seshadri, Bharathi, et al.
Pubblicazione: (2024)
di: Seshadri, Bharathi, et al.
Pubblicazione: (2024)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
di: Rahman, Md Nafiu, et al.
Pubblicazione: (2026)
di: Rahman, Md Nafiu, et al.
Pubblicazione: (2026)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
di: Cusick, James J.
Pubblicazione: (2025)
di: Cusick, James J.
Pubblicazione: (2025)
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
di: Cheng, Yiran, et al.
Pubblicazione: (2024)
di: Cheng, Yiran, et al.
Pubblicazione: (2024)
Many Tools, Few Exploitable Vulnerabilities: A Survey of 246 Static Code Analyzers for Security
di: Hermann, Kevin, et al.
Pubblicazione: (2026)
di: Hermann, Kevin, et al.
Pubblicazione: (2026)
The Secret Life of CVEs
di: Przymus, Piotr, et al.
Pubblicazione: (2025)
di: Przymus, Piotr, et al.
Pubblicazione: (2025)
Trusting code in the wild: Exploring contributor reputation measures to review dependencies in the Rust ecosystem
di: Hamer, Sivana, et al.
Pubblicazione: (2024)
di: Hamer, Sivana, et al.
Pubblicazione: (2024)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
di: Rahman, Imranur, et al.
Pubblicazione: (2024)
di: Rahman, Imranur, et al.
Pubblicazione: (2024)
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
di: Hamer, Sivana, et al.
Pubblicazione: (2025)
di: Hamer, Sivana, et al.
Pubblicazione: (2025)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
di: Wang, Fuwei, et al.
Pubblicazione: (2024)
di: Wang, Fuwei, et al.
Pubblicazione: (2024)
An Extensive Comparison of Static Application Security Testing Tools
di: Esposito, Matteo, et al.
Pubblicazione: (2024)
di: Esposito, Matteo, et al.
Pubblicazione: (2024)
Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils
di: Hamer, Sivana, et al.
Pubblicazione: (2025)
di: Hamer, Sivana, et al.
Pubblicazione: (2025)
"I Don't Use AI for Everything": Exploring Utility, Attitude, and Responsibility of AI-empowered Tools in Software Development
di: Pan, Shidong, et al.
Pubblicazione: (2024)
di: Pan, Shidong, et al.
Pubblicazione: (2024)
Just another copy and paste? Comparing the security vulnerabilities of ChatGPT generated code and StackOverflow answers
di: Hamer, Sivana, et al.
Pubblicazione: (2024)
di: Hamer, Sivana, et al.
Pubblicazione: (2024)
Evaluating Large Language Models in detecting Secrets in Android Apps
di: Alecci, Marco, et al.
Pubblicazione: (2025)
di: Alecci, Marco, et al.
Pubblicazione: (2025)
Decoding Secret Memorization in Code LLMs Through Token-Level Characterization
di: Nie, Yuqing, et al.
Pubblicazione: (2024)
di: Nie, Yuqing, et al.
Pubblicazione: (2024)
Automatically Detecting Checked-In Secrets in Android Apps: How Far Are We?
di: Li, Kevin, et al.
Pubblicazione: (2024)
di: Li, Kevin, et al.
Pubblicazione: (2024)
A Broad Comparative Evaluation of Software Debloating Tools
di: Brown, Michael D., et al.
Pubblicazione: (2023)
di: Brown, Michael D., et al.
Pubblicazione: (2023)
A Static Analysis of Popular C Packages in Linux
di: Ruohonen, Jukka, et al.
Pubblicazione: (2024)
di: Ruohonen, Jukka, et al.
Pubblicazione: (2024)
Toward an Android Static Analysis Approach for Data Protection
di: Khedkar, Mugdha, et al.
Pubblicazione: (2024)
di: Khedkar, Mugdha, et al.
Pubblicazione: (2024)
Evaluating Software Supply Chain Security in Research Software
di: Hegewald, Richard, et al.
Pubblicazione: (2025)
di: Hegewald, Richard, et al.
Pubblicazione: (2025)
How Far are App Secrets from Being Stolen? A Case Study on Android
di: Wei, Lili, et al.
Pubblicazione: (2025)
di: Wei, Lili, et al.
Pubblicazione: (2025)
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
di: Marquer, Yoann, et al.
Pubblicazione: (2026)
di: Marquer, Yoann, et al.
Pubblicazione: (2026)
UEFI Vulnerability Signature Generation using Static and Symbolic Analysis
di: Shafiuzzaman, Md, et al.
Pubblicazione: (2024)
di: Shafiuzzaman, Md, et al.
Pubblicazione: (2024)
Guiding Symbolic Execution with Static Analysis and LLMs for Vulnerability Discovery
di: Shafiuzzaman, Md, et al.
Pubblicazione: (2026)
di: Shafiuzzaman, Md, et al.
Pubblicazione: (2026)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
di: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Pubblicazione: (2025)
di: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Pubblicazione: (2025)
Establishing Workload Identity for Zero Trust CI/CD: From Secrets to SPIFFE-Based Authentication
di: Avirneni, Surya Teja
Pubblicazione: (2025)
di: Avirneni, Surya Teja
Pubblicazione: (2025)
Software Security in Software-Defined Networking: A Systematic Literature Review
di: Diouf, Moustapha Awwalou, et al.
Pubblicazione: (2025)
di: Diouf, Moustapha Awwalou, et al.
Pubblicazione: (2025)
Scalable Test Generation to Trigger Rare Targets in High-Level Synthesizable IPs for Cloud FPGAs
di: Debnath, Mukta, et al.
Pubblicazione: (2024)
di: Debnath, Mukta, et al.
Pubblicazione: (2024)
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
di: Wang, Shenao, et al.
Pubblicazione: (2026)
di: Wang, Shenao, et al.
Pubblicazione: (2026)
Challenges in Developing Secure Software -- Results of an Interview Study in the German Software Industry
di: Mattukat, Alex R., et al.
Pubblicazione: (2025)
di: Mattukat, Alex R., et al.
Pubblicazione: (2025)
DITING: A Static Analyzer for Identifying Bad Partitioning Issues in TEE Applications
di: Ma, Chengyan, et al.
Pubblicazione: (2025)
di: Ma, Chengyan, et al.
Pubblicazione: (2025)
CrossInspector: A Static Analysis Approach for Cross-Contract Vulnerability Detection
di: Chen, Xiao
Pubblicazione: (2024)
di: Chen, Xiao
Pubblicazione: (2024)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
di: O'Donoghue, Eric, et al.
Pubblicazione: (2025)
di: O'Donoghue, Eric, et al.
Pubblicazione: (2025)
An Introduction to Adaptive Software Security
di: Nia, Mehran Alidoost
Pubblicazione: (2023)
di: Nia, Mehran Alidoost
Pubblicazione: (2023)
Documenti analoghi
-
RiskHarvester: A Risk-based Tool to Prioritize Secret Removal Efforts in Software Artifacts
di: Basak, Setu Kumar, et al.
Pubblicazione: (2025) -
Asset-centric Threat Modeling for AI-based Systems
di: von der Assen, Jan, et al.
Pubblicazione: (2024) -
Attackers reveal their arsenal: An investigation of adversarial techniques in CTI reports
di: Rahman, Md Rayhanur, et al.
Pubblicazione: (2024) -
Verifiable Provenance of Software Artifacts with Zero-Knowledge Compilation
di: Ron, Javier, et al.
Pubblicazione: (2026) -
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
di: Seth, Aishwarya, et al.
Pubblicazione: (2023)