The Secrets Must Not Flow: Scaling Security Verification to Large Codebases (extended version)
Fuente:
arXiv
Guardado en:
| Autores principales: | Arquint, Linard, Kishor, Samarth, Koenig, Jason R., Dodds, Joey, Kroening, Daniel, Müller, Peter |
|---|---|
| Formato: | Preprint |
| Publicado: |
2025
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
The Secrets Must Not Flow: Scaling Security Verification to Large Codebases (artifact)
por: Arquint, Linard, et al.
Publicado: (2025)
por: Arquint, Linard, et al.
Publicado: (2025)
Evaluating Large Language Models in detecting Secrets in Android Apps
por: Alecci, Marco, et al.
Publicado: (2025)
por: Alecci, Marco, et al.
Publicado: (2025)
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
por: Ruohonen, Jukka, et al.
Publicado: (2025)
por: Ruohonen, Jukka, et al.
Publicado: (2025)
The Secret Life of CVEs
por: Przymus, Piotr, et al.
Publicado: (2025)
por: Przymus, Piotr, et al.
Publicado: (2025)
A Large Scale Study of AI-based Binary Function Similarity Detection Techniques for Security Researchers and Practitioners
por: Shi, Jingyi, et al.
Publicado: (2025)
por: Shi, Jingyi, et al.
Publicado: (2025)
An Extensible Framework for Architecture-Based Data Flow Analysis for Information Security
por: Boltz, Nicolas, et al.
Publicado: (2024)
por: Boltz, Nicolas, et al.
Publicado: (2024)
SecMLOps: A Comprehensive Framework for Integrating Security Throughout the MLOps Lifecycle
por: Zhang, Xinrui, et al.
Publicado: (2026)
por: Zhang, Xinrui, et al.
Publicado: (2026)
Decoding Secret Memorization in Code LLMs Through Token-Level Characterization
por: Nie, Yuqing, et al.
Publicado: (2024)
por: Nie, Yuqing, et al.
Publicado: (2024)
Automatically Detecting Checked-In Secrets in Android Apps: How Far Are We?
por: Li, Kevin, et al.
Publicado: (2024)
por: Li, Kevin, et al.
Publicado: (2024)
Secure Coding with AI -- From Detection to Repair
por: Belozerov, Vladislav, et al.
Publicado: (2025)
por: Belozerov, Vladislav, et al.
Publicado: (2025)
Verbatim Data Transcription Failures in LLM Code Generation: A State-Tracking Stress Test
por: Haque, Mohd Ariful, et al.
Publicado: (2026)
por: Haque, Mohd Ariful, et al.
Publicado: (2026)
How Far are App Secrets from Being Stolen? A Case Study on Android
por: Wei, Lili, et al.
Publicado: (2025)
por: Wei, Lili, et al.
Publicado: (2025)
Establishing Workload Identity for Zero Trust CI/CD: From Secrets to SPIFFE-Based Authentication
por: Avirneni, Surya Teja
Publicado: (2025)
por: Avirneni, Surya Teja
Publicado: (2025)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
por: Rahman, Md Nafiu, et al.
Publicado: (2026)
por: Rahman, Md Nafiu, et al.
Publicado: (2026)
RiskHarvester: A Risk-based Tool to Prioritize Secret Removal Efforts in Software Artifacts
por: Basak, Setu Kumar, et al.
Publicado: (2025)
por: Basak, Setu Kumar, et al.
Publicado: (2025)
AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts
por: Basak, Setu Kumar, et al.
Publicado: (2024)
por: Basak, Setu Kumar, et al.
Publicado: (2024)
Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis
por: Pecka, Nicholas, et al.
Publicado: (2025)
por: Pecka, Nicholas, et al.
Publicado: (2025)
Large Language Models for Secure Code Assessment: A Multi-Language Empirical Study
por: Dozono, Kohei, et al.
Publicado: (2024)
por: Dozono, Kohei, et al.
Publicado: (2024)
Toward Secure Web to ERP Payment Flows: A Case Study of HTTP Header Trust Failures in SAP Based Systems
por: Dini, Vick
Publicado: (2026)
por: Dini, Vick
Publicado: (2026)
GenSIaC: Toward Security-Aware Infrastructure-as-Code Generation with Large Language Models
por: Li, Yikun, et al.
Publicado: (2025)
por: Li, Yikun, et al.
Publicado: (2025)
A Data-Mining Based Study of Security Vulnerability Types and Their Mitigation in Different Languages
por: Antal, Gábor, et al.
Publicado: (2024)
por: Antal, Gábor, et al.
Publicado: (2024)
Towards Efficient Verification of Constant-Time Cryptographic Implementations
por: Cai, Luwei, et al.
Publicado: (2024)
por: Cai, Luwei, et al.
Publicado: (2024)
DecipherGuard: Understanding and Deciphering Jailbreak Prompts for a Safer Deployment of Intelligent Software Systems
por: Yang, Rui, et al.
Publicado: (2025)
por: Yang, Rui, et al.
Publicado: (2025)
Security study based on the Chatgptplugin system: ldentifying Security Vulnerabilities
por: Ren, Ruomai
Publicado: (2025)
por: Ren, Ruomai
Publicado: (2025)
Leveraging Security Observability to Strengthen Security of Digital Ecosystem Architecture
por: Ramachandran, Renjith
Publicado: (2024)
por: Ramachandran, Renjith
Publicado: (2024)
Security Incentivization: An Empirical Study of how Micropayments Impact Code Security
por: Rass, Stefan, et al.
Publicado: (2026)
por: Rass, Stefan, et al.
Publicado: (2026)
KVerus: Scalable and Resilient Formal Verification Proof Generation for Rust Code
por: Liu, Yuwei, et al.
Publicado: (2026)
por: Liu, Yuwei, et al.
Publicado: (2026)
AutoFirm: Automatically Identifying Reused Libraries inside IoT Firmware at Large-Scale
por: Chen, YongLe, et al.
Publicado: (2024)
por: Chen, YongLe, et al.
Publicado: (2024)
CEBin: A Cost-Effective Framework for Large-Scale Binary Code Similarity Detection
por: Wang, Hao, et al.
Publicado: (2024)
por: Wang, Hao, et al.
Publicado: (2024)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
por: Okafor, Chinenye, et al.
Publicado: (2024)
por: Okafor, Chinenye, et al.
Publicado: (2024)
How Secure is Secure Code Generation? Adversarial Prompts Put LLM Defenses to the Test
por: Tessa, Melissa, et al.
Publicado: (2026)
por: Tessa, Melissa, et al.
Publicado: (2026)
Numeric Truncation Security Predicate
por: Mezhuev, Timofey, et al.
Publicado: (2023)
por: Mezhuev, Timofey, et al.
Publicado: (2023)
LLM Security Guard for Code
por: Kavian, Arya, et al.
Publicado: (2024)
por: Kavian, Arya, et al.
Publicado: (2024)
An Introduction to Adaptive Software Security
por: Nia, Mehran Alidoost
Publicado: (2023)
por: Nia, Mehran Alidoost
Publicado: (2023)
Securing Tomorrow's Smart Cities: Investigating Software Security in Internet of Vehicles and Deep Learning Technologies
por: Jain, Ridhi, et al.
Publicado: (2024)
por: Jain, Ridhi, et al.
Publicado: (2024)
KEENHash: Hashing Programs into Function-Aware Embeddings for Large-Scale Binary Code Similarity Analysis
por: Liu, Zhijie, et al.
Publicado: (2025)
por: Liu, Zhijie, et al.
Publicado: (2025)
Give LLMs a Security Course: Securing Retrieval-Augmented Code Generation via Knowledge Injection
por: Lin, Bo, et al.
Publicado: (2025)
por: Lin, Bo, et al.
Publicado: (2025)
Broken by Default: A Formal Verification Study of Security Vulnerabilities in AI-Generated Code
por: Blain, Dominik, et al.
Publicado: (2026)
por: Blain, Dominik, et al.
Publicado: (2026)
LibScan: Smart Contract Library Misuse Detection with Iterative Feedback and Static Verification
por: Wang, Yishun, et al.
Publicado: (2026)
por: Wang, Yishun, et al.
Publicado: (2026)
An Empirical Study on the Security Vulnerabilities of GPTs
por: Wu, Tong, et al.
Publicado: (2025)
por: Wu, Tong, et al.
Publicado: (2025)
Ejemplares similares
-
The Secrets Must Not Flow: Scaling Security Verification to Large Codebases (artifact)
por: Arquint, Linard, et al.
Publicado: (2025) -
Evaluating Large Language Models in detecting Secrets in Android Apps
por: Alecci, Marco, et al.
Publicado: (2025) -
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
por: Ruohonen, Jukka, et al.
Publicado: (2025) -
The Secret Life of CVEs
por: Przymus, Piotr, et al.
Publicado: (2025) -
A Large Scale Study of AI-based Binary Function Similarity Detection Techniques for Security Researchers and Practitioners
por: Shi, Jingyi, et al.
Publicado: (2025)