Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis
Fuente:
arXiv
Saved in:
| Main Authors: | Pecka, Nicholas, Othmane, Lotfi Ben, Bryce, Renee |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Semi-Automated Threat Modeling of Cloud-Based Systems Through Extracting Software Architecture from Configuration and Network Flow
by: Pecka, Nicholas, et al.
Published: (2026)
by: Pecka, Nicholas, et al.
Published: (2026)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024)
by: Rahman, Imranur, et al.
Published: (2024)
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
by: Marquer, Yoann, et al.
Published: (2026)
by: Marquer, Yoann, et al.
Published: (2026)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Unlocking Reproducibility: Automating re-Build Process for Open-Source Software
by: Hassanshahi, Behnaz, et al.
Published: (2025)
by: Hassanshahi, Behnaz, et al.
Published: (2025)
Software Security Analysis in 2030 and Beyond: A Research Roadmap
by: Böhme, Marcel, et al.
Published: (2024)
by: Böhme, Marcel, et al.
Published: (2024)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
by: Schmid, Larissa, et al.
Published: (2026)
by: Schmid, Larissa, et al.
Published: (2026)
An Introduction to Adaptive Software Security
by: Nia, Mehran Alidoost
Published: (2023)
by: Nia, Mehran Alidoost
Published: (2023)
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Using AI Assistants in Software Development: A Qualitative Study on Security Practices and Concerns
by: Klemmer, Jan H., et al.
Published: (2024)
by: Klemmer, Jan H., et al.
Published: (2024)
Software Security in Software-Defined Networking: A Systematic Literature Review
by: Diouf, Moustapha Awwalou, et al.
Published: (2025)
by: Diouf, Moustapha Awwalou, et al.
Published: (2025)
SecDOAR: A Software Reference Architecture for Security Data Orchestration, Analysis and Reporting
by: Chauhan, Muhammad Aufeef, et al.
Published: (2024)
by: Chauhan, Muhammad Aufeef, et al.
Published: (2024)
VulEval: Towards Repository-Level Evaluation of Software Vulnerability Detection
by: Wen, Xin-Cheng, et al.
Published: (2024)
by: Wen, Xin-Cheng, et al.
Published: (2024)
Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
by: Ayala, Jessy, et al.
Published: (2025)
by: Ayala, Jessy, et al.
Published: (2025)
Challenges in Developing Secure Software -- Results of an Interview Study in the German Software Industry
by: Mattukat, Alex R., et al.
Published: (2025)
by: Mattukat, Alex R., et al.
Published: (2025)
APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching
by: Nong, Yu, et al.
Published: (2024)
by: Nong, Yu, et al.
Published: (2024)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
by: O'Donoghue, Eric, et al.
Published: (2025)
by: O'Donoghue, Eric, et al.
Published: (2025)
Clawdrain: Exploiting Tool-Calling Chains for Stealthy Token Exhaustion in OpenClaw Agents
by: Dong, Ben, et al.
Published: (2026)
by: Dong, Ben, et al.
Published: (2026)
Reverse Engineering and Control-Aware Security Analysis of the ArduPilot UAV Framework
by: Konapalli, Yasaswini, et al.
Published: (2025)
by: Konapalli, Yasaswini, et al.
Published: (2025)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
by: Ruan, Bonan, et al.
Published: (2026)
by: Ruan, Bonan, et al.
Published: (2026)
OriginPruner: Leveraging Method Origins for Guided Call Graph Pruning
by: Mir, Amir M., et al.
Published: (2024)
by: Mir, Amir M., et al.
Published: (2024)
Building Call Graph of WebAssembly Programs via Abstract Semantics
by: Paccamiccio, Mattia, et al.
Published: (2024)
by: Paccamiccio, Mattia, et al.
Published: (2024)
Securing Tomorrow's Smart Cities: Investigating Software Security in Internet of Vehicles and Deep Learning Technologies
by: Jain, Ridhi, et al.
Published: (2024)
by: Jain, Ridhi, et al.
Published: (2024)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
In Specs we Trust? Conformance-Analysis of Implementation to Specifications in Node-RED and Associated Security Risks
by: Schneider, Simon, et al.
Published: (2025)
by: Schneider, Simon, et al.
Published: (2025)
How to Secure Existing C and C++ Software without Memory Safety
by: Erlingsson, Úlfar
Published: (2025)
by: Erlingsson, Úlfar
Published: (2025)
Generating Proof-of-Vulnerability Tests to Help Enhance the Security of Complex Software
by: Kanchi, Shravya, et al.
Published: (2026)
by: Kanchi, Shravya, et al.
Published: (2026)
A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
GenSIaC: Toward Security-Aware Infrastructure-as-Code Generation with Large Language Models
by: Li, Yikun, et al.
Published: (2025)
by: Li, Yikun, et al.
Published: (2025)
FCGHunter: Towards Evaluating Robustness of Graph-Based Android Malware Detection
by: Song, Shiwen, et al.
Published: (2025)
by: Song, Shiwen, et al.
Published: (2025)
AIM: Automated Input Set Minimization for Metamorphic Security Testing
by: Chaleshtari, Nazanin Bayati, et al.
Published: (2024)
by: Chaleshtari, Nazanin Bayati, et al.
Published: (2024)
Profile of Vulnerability Remediations in Dependencies Using Graph Analysis
by: Vera, Fernando, et al.
Published: (2024)
by: Vera, Fernando, et al.
Published: (2024)
RiskHarvester: A Risk-based Tool to Prioritize Secret Removal Efforts in Software Artifacts
by: Basak, Setu Kumar, et al.
Published: (2025)
by: Basak, Setu Kumar, et al.
Published: (2025)
Assessing the Software Security Comprehension of Large Language Models
by: Siddiq, Mohammed Latif, et al.
Published: (2025)
by: Siddiq, Mohammed Latif, et al.
Published: (2025)
Automatic Selection of Protections to Mitigate Risks Against Software Applications
by: Canavese, Daniele, et al.
Published: (2025)
by: Canavese, Daniele, et al.
Published: (2025)
Similar Items
-
Semi-Automated Threat Modeling of Cloud-Based Systems Through Extracting Software Architecture from Configuration and Network Flow
by: Pecka, Nicholas, et al.
Published: (2026) -
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024) -
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
by: Marquer, Yoann, et al.
Published: (2026) -
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024) -
Unlocking Reproducibility: Automating re-Build Process for Open-Source Software
by: Hassanshahi, Behnaz, et al.
Published: (2025)