Longitudinal Analyses of SAST Tools: A CodeQL Case Study
Fuente:
arXiv
Saved in:
| Main Authors: | Ferrand, Jean-Charles Noirot, Domico, Kyle, Beugin, Yohan, McDaniel, Patrick |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
The Role of Learning in Attacking ML-based Network Intrusion Detection
by: Domico, Kyle, et al.
Published: (2026)
by: Domico, Kyle, et al.
Published: (2026)
Targeting Alignment: Extracting Safety Classifiers of Aligned LLMs
by: Ferrand, Jean-Charles Noirot, et al.
Published: (2025)
by: Ferrand, Jean-Charles Noirot, et al.
Published: (2025)
LibIHT: A Hardware-Based Approach to Efficient and Evasion-Resistant Dynamic Binary Analysis
by: Zhao, Changyu, et al.
Published: (2025)
by: Zhao, Changyu, et al.
Published: (2025)
A Public and Reproducible Assessment of the Topics API on Real Data
by: Beugin, Yohan, et al.
Published: (2024)
by: Beugin, Yohan, et al.
Published: (2024)
Technical Report: The Need for a (Research) Sandstorm through the Privacy Sandbox
by: Beugin, Yohan, et al.
Published: (2025)
by: Beugin, Yohan, et al.
Published: (2025)
Adversarial Agents: Black-Box Evasion Attacks with Reinforcement Learning
by: Domico, Kyle, et al.
Published: (2025)
by: Domico, Kyle, et al.
Published: (2025)
Secure IP Address Allocation at Cloud Scale
by: Pauley, Eric, et al.
Published: (2022)
by: Pauley, Eric, et al.
Published: (2022)
Characterizing the Modification Space of Signature IDS Rules
by: Guide, Ryan, et al.
Published: (2024)
by: Guide, Ryan, et al.
Published: (2024)
Efficient Storage Integrity in Adversarial Settings
by: Burke, Quinn, et al.
Published: (2025)
by: Burke, Quinn, et al.
Published: (2025)
ParTEETor: A System for Partial Deployments of TEEs within Tor
by: King, Rachel, et al.
Published: (2024)
by: King, Rachel, et al.
Published: (2024)
Finding 709 Defects in 258 Projects: An Experience Report on Applying CodeQL to Open-Source Embedded Software (Experience Paper) -- Extended Report
by: Shen, Mingjie, et al.
Published: (2023)
by: Shen, Mingjie, et al.
Published: (2023)
Longitudinal Analyses of Static Analysis Tools: A CodeQL Case Study
by: Anonymous, Anonymous
Published: (2026)
by: Anonymous, Anonymous
Published: (2026)
Securing Cloud File Systems with Trusted Execution
by: Burke, Quinn, et al.
Published: (2023)
by: Burke, Quinn, et al.
Published: (2023)
Deserialization Gadget Chains are not a Pathological Problem in Android:an In-Depth Study of Java Gadget Chains in AOSP
by: Kreyssig, Bruno, et al.
Published: (2025)
by: Kreyssig, Bruno, et al.
Published: (2025)
LLM vs. SAST: A Technical Analysis on Detecting Coding Bugs of GPT4-Advanced Data Analysis
by: Tehrani, Madjid G., et al.
Published: (2025)
by: Tehrani, Madjid G., et al.
Published: (2025)
Analysing India's Cyber Warfare Readiness and Developing a Defence Strategy
by: Fernandes, Yohan, et al.
Published: (2024)
by: Fernandes, Yohan, et al.
Published: (2024)
PrediQL: Automated Testing of GraphQL APIs with LLMs
by: Liu, Shaolun, et al.
Published: (2025)
by: Liu, Shaolun, et al.
Published: (2025)
It's a Feature, Not a Bug: Secure and Auditable State Rollback for Confidential Cloud Applications
by: Burke, Quinn, et al.
Published: (2025)
by: Burke, Quinn, et al.
Published: (2025)
VIVID: A Novel Approach to Remediation Prioritization in Static Application Security Testing (SAST)
by: Budhwani, Naeem, et al.
Published: (2025)
by: Budhwani, Naeem, et al.
Published: (2025)
LLM-Driven SAST-Genius: A Hybrid Static Analysis Framework for Comprehensive and Actionable Security
by: Agrawal, Vaibhav, et al.
Published: (2025)
by: Agrawal, Vaibhav, et al.
Published: (2025)
Err on the Side of Texture: Texture Bias on Real Data
by: Hoak, Blaine, et al.
Published: (2024)
by: Hoak, Blaine, et al.
Published: (2024)
ARMOR: Aligning Secure and Safe Large Language Models via Meticulous Reasoning
by: Zhao, Zhengyue, et al.
Published: (2025)
by: Zhao, Zhengyue, et al.
Published: (2025)
On Scalable Integrity Checking for Secure Cloud Disks
by: Burke, Quinn, et al.
Published: (2024)
by: Burke, Quinn, et al.
Published: (2024)
A Practical Guideline and Taxonomy to LLVM's Control Flow Integrity
by: Houy, Sabine, et al.
Published: (2025)
by: Houy, Sabine, et al.
Published: (2025)
A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems
by: Wu, Fangzhou, et al.
Published: (2024)
by: Wu, Fangzhou, et al.
Published: (2024)
SastBench: A Benchmark for Testing Agentic SAST Triage
by: Feiglin, Jake, et al.
Published: (2026)
by: Feiglin, Jake, et al.
Published: (2026)
On the Robustness Tradeoff in Fine-Tuning
by: Li, Kunyang, et al.
Published: (2025)
by: Li, Kunyang, et al.
Published: (2025)
Overthinking Loops in Agents: A Structural Risk via MCP Tools
by: Lee, Yohan, et al.
Published: (2026)
by: Lee, Yohan, et al.
Published: (2026)
GraphQLer: Enhancing GraphQL Security with Context-Aware API Testing
by: Tsai, Omar, et al.
Published: (2025)
by: Tsai, Omar, et al.
Published: (2025)
Your Code Secret Belongs to Me: Neural Code Completion Tools Can Memorize Hard-Coded Credentials
by: Huang, Yizhan, et al.
Published: (2023)
by: Huang, Yizhan, et al.
Published: (2023)
From Tool Orchestration to Code Execution: A Study of MCP Design Choices
by: Felendler, Yuval, et al.
Published: (2026)
by: Felendler, Yuval, et al.
Published: (2026)
A Case Study on the Use of Representativeness Bias as a Defense Against Adversarial Cyber Threats
by: Hitaj, Briland, et al.
Published: (2025)
by: Hitaj, Briland, et al.
Published: (2025)
Aligning Security Compliance and DevOps: A Longitudinal Study
by: Moyón, Fabiola, et al.
Published: (2025)
by: Moyón, Fabiola, et al.
Published: (2025)
Fusing Feature Engineering and Deep Learning: A Case Study for Malware Classification
by: Gibert, Daniel, et al.
Published: (2022)
by: Gibert, Daniel, et al.
Published: (2022)
Securing Stack Smashing Protection in WebAssembly Applications
by: Michaud, Quentin, et al.
Published: (2024)
by: Michaud, Quentin, et al.
Published: (2024)
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
by: Maloyan, Narek, et al.
Published: (2026)
by: Maloyan, Narek, et al.
Published: (2026)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
by: Wang, Fuwei, et al.
Published: (2024)
by: Wang, Fuwei, et al.
Published: (2024)
A Longitudinal Measurement Study of Log4Shell Exploitation from a Reactive Network Telescope
by: Singh, Aakash, et al.
Published: (2026)
by: Singh, Aakash, et al.
Published: (2026)
When Code Crosses Borders: A Security-Centric Study of LLM-based Code Translation
by: Chang, Hailong, et al.
Published: (2025)
by: Chang, Hailong, et al.
Published: (2025)
Mitigating Fine-tuning based Jailbreak Attack with Backdoor Enhanced Safety Alignment
by: Wang, Jiongxiao, et al.
Published: (2024)
by: Wang, Jiongxiao, et al.
Published: (2024)
Similar Items
-
The Role of Learning in Attacking ML-based Network Intrusion Detection
by: Domico, Kyle, et al.
Published: (2026) -
Targeting Alignment: Extracting Safety Classifiers of Aligned LLMs
by: Ferrand, Jean-Charles Noirot, et al.
Published: (2025) -
LibIHT: A Hardware-Based Approach to Efficient and Evasion-Resistant Dynamic Binary Analysis
by: Zhao, Changyu, et al.
Published: (2025) -
A Public and Reproducible Assessment of the Topics API on Real Data
by: Beugin, Yohan, et al.
Published: (2024) -
Technical Report: The Need for a (Research) Sandstorm through the Privacy Sandbox
by: Beugin, Yohan, et al.
Published: (2025)