[{"publication":"International Symposium on Advanced Security on Software and Systems (ASSS)","citation":{"bibtex":"@article{Holzinger_Bodden_2021, title={A Systematic Hardening of Java’s Information Hiding}, journal={International Symposium on Advanced Security on Software and Systems (ASSS)}, author={Holzinger, Philipp and Bodden, Eric}, year={2021} }","ama":"Holzinger P, Bodden E. A Systematic Hardening of Java’s Information Hiding. <i>International Symposium on Advanced Security on Software and Systems (ASSS)</i>. Published online 2021.","mla":"Holzinger, Philipp, and Eric Bodden. “A Systematic Hardening of Java’s Information Hiding.” <i>International Symposium on Advanced Security on Software and Systems (ASSS)</i>, 2021.","short":"P. Holzinger, E. Bodden, International Symposium on Advanced Security on Software and Systems (ASSS) (2021).","chicago":"Holzinger, Philipp, and Eric Bodden. “A Systematic Hardening of Java’s Information Hiding.” <i>International Symposium on Advanced Security on Software and Systems (ASSS)</i>, 2021.","ieee":"P. Holzinger and E. Bodden, “A Systematic Hardening of Java’s Information Hiding,” <i>International Symposium on Advanced Security on Software and Systems (ASSS)</i>, 2021.","apa":"Holzinger, P., &#38; Bodden, E. (2021). A Systematic Hardening of Java’s Information Hiding. <i>International Symposium on Advanced Security on Software and Systems (ASSS)</i>."},"date_created":"2021-04-08T11:24:06Z","type":"journal_article","department":[{"_id":"76"}],"status":"public","year":"2021","title":"A Systematic Hardening of Java's Information Hiding","author":[{"first_name":"Philipp","last_name":"Holzinger","full_name":"Holzinger, Philipp"},{"id":"59256","orcid":"0000-0003-3470-3647","last_name":"Bodden","first_name":"Eric","full_name":"Bodden, Eric"}],"date_updated":"2022-01-06T06:55:06Z","main_file_link":[{"url":"https://www.bodden.de/pubs/hb21systematic.pdf"}],"language":[{"iso":"eng"}],"_id":"21597","user_id":"5786"},{"author":[{"last_name":"Bonifacio","first_name":"Rodrigo","full_name":"Bonifacio, Rodrigo"},{"last_name":"Krüger","first_name":"Stefan","full_name":"Krüger, Stefan"},{"full_name":"Narasimhan, Krishna","first_name":"Krishna","last_name":"Narasimhan"},{"full_name":"Bodden, Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647","first_name":"Eric","id":"59256"},{"last_name":"Mezini","first_name":"Mira","full_name":"Mezini, Mira"}],"status":"public","title":"Dealing with Variability in API Misuse Specification","year":"2021","date_updated":"2022-01-06T06:55:06Z","_id":"21599","language":[{"iso":"eng"}],"user_id":"5786","citation":{"ieee":"R. Bonifacio, S. Krüger, K. Narasimhan, E. Bodden, and M. Mezini, “Dealing with Variability in API Misuse Specification,” <i>European Conference on Object-Oriented Programming (ECOOP)</i>, 2021.","apa":"Bonifacio, R., Krüger, S., Narasimhan, K., Bodden, E., &#38; Mezini, M. (2021). Dealing with Variability in API Misuse Specification. <i>European Conference on Object-Oriented Programming (ECOOP)</i>.","chicago":"Bonifacio, Rodrigo, Stefan Krüger, Krishna Narasimhan, Eric Bodden, and Mira Mezini. “Dealing with Variability in API Misuse Specification.” <i>European Conference on Object-Oriented Programming (ECOOP)</i>, 2021.","short":"R. Bonifacio, S. Krüger, K. Narasimhan, E. Bodden, M. Mezini, European Conference on Object-Oriented Programming (ECOOP) (2021).","mla":"Bonifacio, Rodrigo, et al. “Dealing with Variability in API Misuse Specification.” <i>European Conference on Object-Oriented Programming (ECOOP)</i>, 2021.","bibtex":"@article{Bonifacio_Krüger_Narasimhan_Bodden_Mezini_2021, title={Dealing with Variability in API Misuse Specification}, journal={European Conference on Object-Oriented Programming (ECOOP)}, author={Bonifacio, Rodrigo and Krüger, Stefan and Narasimhan, Krishna and Bodden, Eric and Mezini, Mira}, year={2021} }","ama":"Bonifacio R, Krüger S, Narasimhan K, Bodden E, Mezini M. Dealing with Variability in API Misuse Specification. <i>European Conference on Object-Oriented Programming (ECOOP)</i>. Published online 2021."},"publication":"European Conference on Object-Oriented Programming (ECOOP)","date_created":"2021-04-08T11:25:43Z","department":[{"_id":"76"}],"type":"journal_article"},{"author":[{"full_name":"Kummita, Sriteja","last_name":"Kummita","first_name":"Sriteja"},{"full_name":"Piskachev, Goran","last_name":"Piskachev","first_name":"Goran"},{"full_name":"Spath, Johannes","first_name":"Johannes","last_name":"Spath"},{"first_name":"Eric","last_name":"Bodden","full_name":"Bodden, Eric"}],"year":"2021","status":"public","title":"Qualitative and Quantitative Analysis of Callgraph Algorithms for Python","date_updated":"2022-01-06T06:55:50Z","publication_status":"published","language":[{"iso":"eng"}],"_id":"23374","doi":"10.1109/iccq51190.2021.9392986","user_id":"5786","citation":{"bibtex":"@inproceedings{Kummita_Piskachev_Spath_Bodden_2021, title={Qualitative and Quantitative Analysis of Callgraph Algorithms for Python}, DOI={<a href=\"https://doi.org/10.1109/iccq51190.2021.9392986\">10.1109/iccq51190.2021.9392986</a>}, booktitle={2021 International Conference on Code Quality (ICCQ)}, author={Kummita, Sriteja and Piskachev, Goran and Spath, Johannes and Bodden, Eric}, year={2021} }","ama":"Kummita S, Piskachev G, Spath J, Bodden E. Qualitative and Quantitative Analysis of Callgraph Algorithms for Python. In: <i>2021 International Conference on Code Quality (ICCQ)</i>. ; 2021. doi:<a href=\"https://doi.org/10.1109/iccq51190.2021.9392986\">10.1109/iccq51190.2021.9392986</a>","mla":"Kummita, Sriteja, et al. “Qualitative and Quantitative Analysis of Callgraph Algorithms for Python.” <i>2021 International Conference on Code Quality (ICCQ)</i>, 2021, doi:<a href=\"https://doi.org/10.1109/iccq51190.2021.9392986\">10.1109/iccq51190.2021.9392986</a>.","short":"S. Kummita, G. Piskachev, J. Spath, E. Bodden, in: 2021 International Conference on Code Quality (ICCQ), 2021.","chicago":"Kummita, Sriteja, Goran Piskachev, Johannes Spath, and Eric Bodden. “Qualitative and Quantitative Analysis of Callgraph Algorithms for Python.” In <i>2021 International Conference on Code Quality (ICCQ)</i>, 2021. <a href=\"https://doi.org/10.1109/iccq51190.2021.9392986\">https://doi.org/10.1109/iccq51190.2021.9392986</a>.","ieee":"S. Kummita, G. Piskachev, J. Spath, and E. Bodden, “Qualitative and Quantitative Analysis of Callgraph Algorithms for Python,” 2021, doi: <a href=\"https://doi.org/10.1109/iccq51190.2021.9392986\">10.1109/iccq51190.2021.9392986</a>.","apa":"Kummita, S., Piskachev, G., Spath, J., &#38; Bodden, E. (2021). Qualitative and Quantitative Analysis of Callgraph Algorithms for Python. <i>2021 International Conference on Code Quality (ICCQ)</i>. <a href=\"https://doi.org/10.1109/iccq51190.2021.9392986\">https://doi.org/10.1109/iccq51190.2021.9392986</a>"},"publication":"2021 International Conference on Code Quality (ICCQ)","date_created":"2021-08-09T12:01:11Z","department":[{"_id":"241"},{"_id":"662"},{"_id":"76"}],"type":"conference"},{"date_created":"2022-02-24T15:44:42Z","type":"conference","department":[{"_id":"76"}],"publication":"2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)","citation":{"ieee":"K. Karakaya and E. Bodden, “SootFX: A Static Code Feature Extraction Tool for Java and Android,” 2021, doi: <a href=\"https://doi.org/10.1109/scam52516.2021.00030\">10.1109/scam52516.2021.00030</a>.","apa":"Karakaya, K., &#38; Bodden, E. (2021). SootFX: A Static Code Feature Extraction Tool for Java and Android. <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>. <a href=\"https://doi.org/10.1109/scam52516.2021.00030\">https://doi.org/10.1109/scam52516.2021.00030</a>","chicago":"Karakaya, Kadiray, and Eric Bodden. “SootFX: A Static Code Feature Extraction Tool for Java and Android.” In <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>. IEEE, 2021. <a href=\"https://doi.org/10.1109/scam52516.2021.00030\">https://doi.org/10.1109/scam52516.2021.00030</a>.","short":"K. Karakaya, E. Bodden, in: 2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM), IEEE, 2021.","mla":"Karakaya, Kadiray, and Eric Bodden. “SootFX: A Static Code Feature Extraction Tool for Java and Android.” <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, IEEE, 2021, doi:<a href=\"https://doi.org/10.1109/scam52516.2021.00030\">10.1109/scam52516.2021.00030</a>.","bibtex":"@inproceedings{Karakaya_Bodden_2021, title={SootFX: A Static Code Feature Extraction Tool for Java and Android}, DOI={<a href=\"https://doi.org/10.1109/scam52516.2021.00030\">10.1109/scam52516.2021.00030</a>}, booktitle={2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)}, publisher={IEEE}, author={Karakaya, Kadiray and Bodden, Eric}, year={2021} }","ama":"Karakaya K, Bodden E. SootFX: A Static Code Feature Extraction Tool for Java and Android. In: <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>. IEEE; 2021. doi:<a href=\"https://doi.org/10.1109/scam52516.2021.00030\">10.1109/scam52516.2021.00030</a>"},"_id":"30084","publisher":"IEEE","doi":"10.1109/scam52516.2021.00030","user_id":"70410","title":"SootFX: A Static Code Feature Extraction Tool for Java and Android","status":"public","year":"2021","author":[{"full_name":"Karakaya, Kadiray","first_name":"Kadiray","last_name":"Karakaya"},{"first_name":"Eric","last_name":"Bodden","full_name":"Bodden, Eric"}],"date_updated":"2022-02-24T15:45:43Z","publication_status":"published"},{"author":[{"id":"60543","full_name":"Schubert, Philipp","last_name":"Schubert","orcid":"0000-0002-8674-1859","first_name":"Philipp"},{"full_name":"Hermann, Ben","orcid":"0000-0001-9848-2017","first_name":"Ben","last_name":"Hermann","id":"66173"},{"id":"59256","first_name":"Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","full_name":"Bodden, Eric"}],"status":"public","title":"Lossless, Persisted Summarization of Static Callgraph, Points-To and Data-Flow Analysis","year":"2021","date_updated":"2022-03-25T07:49:35Z","_id":"21598","language":[{"iso":"eng"}],"main_file_link":[{"open_access":"1","url":"https://drops.dagstuhl.de/opus/volltexte/2021/14045/"}],"user_id":"60543","citation":{"ama":"Schubert P, Hermann B, Bodden E. Lossless, Persisted Summarization of Static Callgraph, Points-To and Data-Flow Analysis. In: <i>European Conference on Object-Oriented Programming (ECOOP)</i>. ; 2021.","short":"P. Schubert, B. Hermann, E. Bodden, in: European Conference on Object-Oriented Programming (ECOOP), 2021.","chicago":"Schubert, Philipp, Ben Hermann, and Eric Bodden. “Lossless, Persisted Summarization of Static Callgraph, Points-To and Data-Flow Analysis.” In <i>European Conference on Object-Oriented Programming (ECOOP)</i>, 2021.","bibtex":"@inproceedings{Schubert_Hermann_Bodden_2021, title={Lossless, Persisted Summarization of Static Callgraph, Points-To and Data-Flow Analysis}, booktitle={European Conference on Object-Oriented Programming (ECOOP)}, author={Schubert, Philipp and Hermann, Ben and Bodden, Eric}, year={2021} }","apa":"Schubert, P., Hermann, B., &#38; Bodden, E. (2021). Lossless, Persisted Summarization of Static Callgraph, Points-To and Data-Flow Analysis. <i>European Conference on Object-Oriented Programming (ECOOP)</i>.","mla":"Schubert, Philipp, et al. “Lossless, Persisted Summarization of Static Callgraph, Points-To and Data-Flow Analysis.” <i>European Conference on Object-Oriented Programming (ECOOP)</i>, 2021.","ieee":"P. Schubert, B. Hermann, and E. Bodden, “Lossless, Persisted Summarization of Static Callgraph, Points-To and Data-Flow Analysis,” 2021."},"publication":"European Conference on Object-Oriented Programming (ECOOP)","project":[{"_id":"3","name":"SFB 901 - Project Area B"},{"name":"SFB 901 - Subproject B4","_id":"12"},{"_id":"1","name":"SFB 901"}],"abstract":[{"text":"Static analysis is used to automatically detect bugs and security breaches, and aids compileroptimization. Whole-program analysis (WPA) can yield high precision, however causes long analysistimes and thus does not match common software-development workflows, making it often impracticalto use for large, real-world applications.This paper thus presents the design and implementation ofModAlyzer, a novel static-analysisapproach that aims at accelerating whole-program analysis by making the analysis modular andcompositional. It shows how to computelossless, persisted summaries for callgraph, points-to anddata-flow information, and it reports under which circumstances this function-level compositionalanalysis outperforms WPA.We implementedModAlyzeras an extension to LLVM and PhASAR, and applied it to 12 real-world C and C++ applications. At analysis time,ModAlyzermodularly and losslessly summarizesthe analysis effect of the library code those applications share, hence avoiding its repeated re-analysis.The experimental results show that the reuse of these summaries can save, on average, 72% ofanalysis time over WPA. Moreover, because it is lossless, the module-wise analysis fully retainsprecision and recall. Surprisingly, as our results show, it sometimes even yields precision superior toWPA. The initial summary generation, on average, takes about 3.67 times as long as WPA.","lang":"eng"}],"date_created":"2021-04-08T11:24:59Z","department":[{"_id":"76"}],"oa":"1","type":"conference"},{"year":"2021","title":"SecuCheck: Engineering configurable taint analysis for software developers","status":"public","author":[{"id":"41936","full_name":"Piskachev, Goran","orcid":"0000-0003-4424-5838","last_name":"Piskachev","first_name":"Goran"},{"first_name":"Ranjith","last_name":"Krishnamurthy","full_name":"Krishnamurthy, Ranjith"},{"id":"59256","full_name":"Bodden, Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","first_name":"Eric"}],"date_updated":"2022-10-20T12:44:31Z","language":[{"iso":"eng"}],"_id":"26407","user_id":"15249","publication":"2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)","citation":{"mla":"Piskachev, Goran, et al. “SecuCheck: Engineering Configurable Taint Analysis for Software Developers.” <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, 2021.","bibtex":"@inproceedings{Piskachev_Krishnamurthy_Bodden_2021, title={SecuCheck: Engineering configurable taint analysis for software developers}, booktitle={2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)}, author={Piskachev, Goran and Krishnamurthy, Ranjith and Bodden, Eric}, year={2021} }","ama":"Piskachev G, Krishnamurthy R, Bodden E. SecuCheck: Engineering configurable taint analysis for software developers. In: <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>. ; 2021.","ieee":"G. Piskachev, R. Krishnamurthy, and E. Bodden, “SecuCheck: Engineering configurable taint analysis for software developers,” 2021.","apa":"Piskachev, G., Krishnamurthy, R., &#38; Bodden, E. (2021). SecuCheck: Engineering configurable taint analysis for software developers. <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>.","chicago":"Piskachev, Goran, Ranjith Krishnamurthy, and Eric Bodden. “SecuCheck: Engineering Configurable Taint Analysis for Software Developers.” In <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, 2021.","short":"G. Piskachev, R. Krishnamurthy, E. Bodden, in: 2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM), 2021."},"date_created":"2021-10-18T12:53:15Z","type":"conference","department":[{"_id":"76"},{"_id":"662"}]},{"citation":{"chicago":"Luo, Linghui, Martin Schäf, Daniel Sanchez, and Eric Bodden. “IDE Support for Cloud-Based Static Analyses.” In <i>Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering</i>, 2021.","short":"L. Luo, M. Schäf, D. Sanchez, E. Bodden, in: Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, 2021.","ieee":"L. Luo, M. Schäf, D. Sanchez, and E. Bodden, “IDE Support for Cloud-Based Static Analyses,” 2021.","apa":"Luo, L., Schäf, M., Sanchez, D., &#38; Bodden, E. (2021). IDE Support for Cloud-Based Static Analyses. <i>Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering</i>.","bibtex":"@inproceedings{Luo_Schäf_Sanchez_Bodden_2021, title={IDE Support for Cloud-Based Static Analyses}, booktitle={Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering}, author={Luo, Linghui and Schäf, Martin and Sanchez, Daniel and Bodden, Eric}, year={2021} }","ama":"Luo L, Schäf M, Sanchez D, Bodden E. IDE Support for Cloud-Based Static Analyses. In: <i>Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering</i>. ; 2021.","mla":"Luo, Linghui, et al. “IDE Support for Cloud-Based Static Analyses.” <i>Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering</i>, 2021."},"publication":"Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering","date_created":"2021-06-17T10:18:05Z","department":[{"_id":"76"}],"type":"conference","author":[{"full_name":"Luo, Linghui","first_name":"Linghui","last_name":"Luo"},{"last_name":"Schäf","first_name":"Martin","full_name":"Schäf, Martin"},{"full_name":"Sanchez, Daniel","first_name":"Daniel","last_name":"Sanchez"},{"full_name":"Bodden, Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","first_name":"Eric","id":"59256"}],"status":"public","title":"IDE Support for Cloud-Based Static Analyses","year":"2021","date_updated":"2022-10-20T13:11:45Z","language":[{"iso":"eng"}],"_id":"22463","user_id":"15249"},{"author":[{"id":"70410","orcid":"https://orcid.org/0000-0001-9266-2084","last_name":"Karakaya","first_name":"Kadiray","full_name":"Karakaya, Kadiray"},{"id":"59256","first_name":"Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647","full_name":"Bodden, Eric"}],"status":"public","title":"SootFX: A Static Code Feature Extraction Tool for Java and Android","year":"2021","date_updated":"2022-10-20T13:09:23Z","language":[{"iso":"eng"}],"_id":"33840","page":"181–186","user_id":"15249","citation":{"mla":"Karakaya, Kadiray, and Eric Bodden. “SootFX: A Static Code Feature Extraction Tool for Java and Android.” <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, 2021, pp. 181–186.","bibtex":"@inproceedings{Karakaya_Bodden_2021, title={SootFX: A Static Code Feature Extraction Tool for Java and Android}, booktitle={2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)}, author={Karakaya, Kadiray and Bodden, Eric}, year={2021}, pages={181–186} }","ama":"Karakaya K, Bodden E. SootFX: A Static Code Feature Extraction Tool for Java and Android. In: <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>. ; 2021:181–186.","ieee":"K. Karakaya and E. Bodden, “SootFX: A Static Code Feature Extraction Tool for Java and Android,” in <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, 2021, pp. 181–186.","apa":"Karakaya, K., &#38; Bodden, E. (2021). SootFX: A Static Code Feature Extraction Tool for Java and Android. <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, 181–186.","chicago":"Karakaya, Kadiray, and Eric Bodden. “SootFX: A Static Code Feature Extraction Tool for Java and Android.” In <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, 181–186, 2021.","short":"K. Karakaya, E. Bodden, in: 2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM), 2021, pp. 181–186."},"publication":"2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)","date_created":"2022-10-20T13:09:08Z","department":[{"_id":"76"}],"type":"conference"},{"publication":"SCAM '21: IEEE International Working Conference on Source Code Analysis and Manipulation (Engineering Track)","citation":{"mla":"Schubert, Philipp, et al. “Into the Woods: Experiences from Building a Dataflow Analysis Framework for C/C++.” <i>SCAM ’21: IEEE International Working Conference on Source Code Analysis and Manipulation (Engineering Track)</i>, 2021.","ama":"Schubert P, Hermann B, Bodden E, Leer R. Into the Woods: Experiences from Building a Dataflow Analysis Framework for C/C++. In: <i>SCAM ’21: IEEE International Working Conference on Source Code Analysis and Manipulation (Engineering Track)</i>. ; 2021.","bibtex":"@inproceedings{Schubert_Hermann_Bodden_Leer_2021, title={Into the Woods: Experiences from Building a Dataflow Analysis Framework for C/C++}, booktitle={SCAM ’21: IEEE International Working Conference on Source Code Analysis and Manipulation (Engineering Track)}, author={Schubert, Philipp and Hermann, Ben and Bodden, Eric and Leer, Richard}, year={2021} }","apa":"Schubert, P., Hermann, B., Bodden, E., &#38; Leer, R. (2021). Into the Woods: Experiences from Building a Dataflow Analysis Framework for C/C++. <i>SCAM ’21: IEEE International Working Conference on Source Code Analysis and Manipulation (Engineering Track)</i>.","ieee":"P. Schubert, B. Hermann, E. Bodden, and R. Leer, “Into the Woods: Experiences from Building a Dataflow Analysis Framework for C/C++,” 2021.","short":"P. Schubert, B. Hermann, E. Bodden, R. Leer, in: SCAM ’21: IEEE International Working Conference on Source Code Analysis and Manipulation (Engineering Track), 2021.","chicago":"Schubert, Philipp, Ben Hermann, Eric Bodden, and Richard Leer. “Into the Woods: Experiences from Building a Dataflow Analysis Framework for C/C++.” In <i>SCAM ’21: IEEE International Working Conference on Source Code Analysis and Manipulation (Engineering Track)</i>, 2021."},"project":[{"name":"SFB 901 - B: SFB 901 - Project Area B","_id":"3"},{"_id":"12","name":"SFB 901 - B4: SFB 901 - Subproject B4"},{"grant_number":"160364472","_id":"1","name":"SFB 901: SFB 901: On-The-Fly Computing - Individualisierte IT-Dienstleistungen in dynamischen Märkten "}],"date_created":"2021-10-18T12:52:12Z","type":"conference","department":[{"_id":"76"}],"title":"Into the Woods: Experiences from Building a Dataflow Analysis Framework for C/C++","year":"2021","status":"public","author":[{"id":"60543","full_name":"Schubert, Philipp","orcid":"0000-0002-8674-1859","first_name":"Philipp","last_name":"Schubert"},{"last_name":"Hermann","orcid":"0000-0001-9848-2017","first_name":"Ben","full_name":"Hermann, Ben","id":"66173"},{"first_name":"Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647","full_name":"Bodden, Eric","id":"59256"},{"last_name":"Leer","first_name":"Richard","full_name":"Leer, Richard"}],"date_updated":"2023-06-15T08:39:55Z","_id":"26406","language":[{"iso":"eng"}],"user_id":"15249"},{"author":[{"full_name":"Shivarpatna Venkatesh, Ashwin Prasad","last_name":"Shivarpatna Venkatesh","first_name":"Ashwin Prasad","id":"66637"},{"last_name":"Bodden","orcid":"0000-0003-3470-3647","first_name":"Eric","full_name":"Bodden, Eric","id":"59256"}],"status":"public","year":"2021","title":"Automated Cell Header Generator for Jupyter Notebooks","date_updated":"2025-04-07T10:21:29Z","language":[{"iso":"eng"}],"_id":"22462","doi":"10.1145/3464968.3468410","user_id":"15249","citation":{"apa":"Shivarpatna Venkatesh, A. P., &#38; Bodden, E. (2021). Automated Cell Header Generator for Jupyter Notebooks. <i>International Workshop on AI and Software Testing/Analysis (AISTA)</i>. <a href=\"https://doi.org/10.1145/3464968.3468410\">https://doi.org/10.1145/3464968.3468410</a>","ieee":"A. P. Shivarpatna Venkatesh and E. Bodden, “Automated Cell Header Generator for Jupyter Notebooks,” 2021, doi: <a href=\"https://doi.org/10.1145/3464968.3468410\">10.1145/3464968.3468410</a>.","short":"A.P. Shivarpatna Venkatesh, E. Bodden, in: International Workshop on AI and Software Testing/Analysis (AISTA), 2021.","chicago":"Shivarpatna Venkatesh, Ashwin Prasad, and Eric Bodden. “Automated Cell Header Generator for Jupyter Notebooks.” In <i>International Workshop on AI and Software Testing/Analysis (AISTA)</i>, 2021. <a href=\"https://doi.org/10.1145/3464968.3468410\">https://doi.org/10.1145/3464968.3468410</a>.","mla":"Shivarpatna Venkatesh, Ashwin Prasad, and Eric Bodden. “Automated Cell Header Generator for Jupyter Notebooks.” <i>International Workshop on AI and Software Testing/Analysis (AISTA)</i>, 2021, doi:<a href=\"https://doi.org/10.1145/3464968.3468410\">10.1145/3464968.3468410</a>.","ama":"Shivarpatna Venkatesh AP, Bodden E. Automated Cell Header Generator for Jupyter Notebooks. In: <i>International Workshop on AI and Software Testing/Analysis (AISTA)</i>. ; 2021. doi:<a href=\"https://doi.org/10.1145/3464968.3468410\">10.1145/3464968.3468410</a>","bibtex":"@inproceedings{Shivarpatna Venkatesh_Bodden_2021, title={Automated Cell Header Generator for Jupyter Notebooks}, DOI={<a href=\"https://doi.org/10.1145/3464968.3468410\">10.1145/3464968.3468410</a>}, booktitle={International Workshop on AI and Software Testing/Analysis (AISTA)}, author={Shivarpatna Venkatesh, Ashwin Prasad and Bodden, Eric}, year={2021} }"},"publication":"International Workshop on AI and Software Testing/Analysis (AISTA)","date_created":"2021-06-17T10:14:48Z","department":[{"_id":"76"}],"type":"conference"},{"project":[{"_id":"107","name":"Reaktor: SFB 901 - Automatisierte Risikoanalyse in Bezug auf Open-Source-Abhängigkeiten (Hektor) (Transferproject T3)"},{"name":"SFB 901: On-The-Fly Computing - Individualisierte IT-Dienstleistungen in dynamischen Märkten","_id":"1"},{"_id":"82","name":"SFB 901; Projektbereich T: Transferprojekte des Sonderforschungsbereichs"},{"name":"SFB 901; TP T3: Automatisierte Risikoanalyse in Bezug auf Open-Source-Abhängigkeiten (Hektor)","_id":"107"}],"citation":{"ama":"Dann AP, Plate H, Hermann B, Ponta SE, Bodden E. Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite. <i>IEEE Transactions on Software Engineering</i>. Published online 2021:1-1. doi:<a href=\"https://doi.org/10.1109/tse.2021.3101739\">10.1109/tse.2021.3101739</a>","bibtex":"@article{Dann_Plate_Hermann_Ponta_Bodden_2021, title={Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite}, DOI={<a href=\"https://doi.org/10.1109/tse.2021.3101739\">10.1109/tse.2021.3101739</a>}, journal={IEEE Transactions on Software Engineering}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Dann, Andreas Peter and Plate, Henrik and Hermann, Ben and Ponta, Serena Elisa and Bodden, Eric}, year={2021}, pages={1–1} }","mla":"Dann, Andreas Peter, et al. “Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite.” <i>IEEE Transactions on Software Engineering</i>, Institute of Electrical and Electronics Engineers (IEEE), 2021, pp. 1–1, doi:<a href=\"https://doi.org/10.1109/tse.2021.3101739\">10.1109/tse.2021.3101739</a>.","chicago":"Dann, Andreas Peter, Henrik Plate, Ben Hermann, Serena Elisa Ponta, and Eric Bodden. “Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite.” <i>IEEE Transactions on Software Engineering</i>, 2021, 1–1. <a href=\"https://doi.org/10.1109/tse.2021.3101739\">https://doi.org/10.1109/tse.2021.3101739</a>.","short":"A.P. Dann, H. Plate, B. Hermann, S.E. Ponta, E. Bodden, IEEE Transactions on Software Engineering (2021) 1–1.","apa":"Dann, A. P., Plate, H., Hermann, B., Ponta, S. E., &#38; Bodden, E. (2021). Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite. <i>IEEE Transactions on Software Engineering</i>, 1–1. <a href=\"https://doi.org/10.1109/tse.2021.3101739\">https://doi.org/10.1109/tse.2021.3101739</a>","ieee":"A. P. Dann, H. Plate, B. Hermann, S. E. Ponta, and E. Bodden, “Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite,” <i>IEEE Transactions on Software Engineering</i>, pp. 1–1, 2021, doi: <a href=\"https://doi.org/10.1109/tse.2021.3101739\">10.1109/tse.2021.3101739</a>."},"publication":"IEEE Transactions on Software Engineering","department":[{"_id":"76"}],"type":"journal_article","keyword":["Software"],"date_created":"2022-05-09T13:02:35Z","publication_status":"published","date_updated":"2025-11-11T14:28:46Z","publication_identifier":{"issn":["0098-5589","1939-3520","2326-3881"]},"author":[{"id":"26886","first_name":"Andreas Peter","last_name":"Dann","full_name":"Dann, Andreas Peter"},{"first_name":"Henrik","last_name":"Plate","full_name":"Plate, Henrik"},{"id":"66173","orcid":"0000-0001-9848-2017","first_name":"Ben","last_name":"Hermann","full_name":"Hermann, Ben"},{"last_name":"Ponta","first_name":"Serena Elisa","full_name":"Ponta, Serena Elisa"},{"id":"59256","first_name":"Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","full_name":"Bodden, Eric"}],"year":"2021","title":"Identifying Challenges for OSS Vulnerability Scanners - A Study &amp; Test Suite","status":"public","user_id":"477","doi":"10.1109/tse.2021.3101739","publisher":"Institute of Electrical and Electronics Engineers (IEEE)","_id":"31132","language":[{"iso":"eng"}],"page":"1-1"},{"author":[{"full_name":"Schubert, Philipp","first_name":"Philipp","orcid":"0000-0002-8674-1859","last_name":"Schubert","id":"60543"},{"last_name":"Sattler","first_name":"Florian","full_name":"Sattler, Florian"},{"full_name":"Schiebel, Fabian Benedikt","first_name":"Fabian Benedikt","orcid":"0009-0008-6867-9802","last_name":"Schiebel","id":"55745"},{"first_name":"Ben","last_name":"Hermann","orcid":"0000-0001-9848-2017","full_name":"Hermann, Ben","id":"66173"},{"last_name":"Bodden","orcid":"0000-0003-3470-3647","first_name":"Eric","full_name":"Bodden, Eric","id":"59256"}],"year":"2021","status":"public","title":"Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++","date_updated":"2025-12-04T10:43:01Z","language":[{"iso":"eng"}],"_id":"26405","user_id":"15249","citation":{"mla":"Schubert, Philipp, et al. “Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++.” <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, 2021.","bibtex":"@inproceedings{Schubert_Sattler_Schiebel_Hermann_Bodden_2021, title={Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++}, booktitle={2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)}, author={Schubert, Philipp and Sattler, Florian and Schiebel, Fabian Benedikt and Hermann, Ben and Bodden, Eric}, year={2021} }","ama":"Schubert P, Sattler F, Schiebel FB, Hermann B, Bodden E. Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++. In: <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>. ; 2021.","ieee":"P. Schubert, F. Sattler, F. B. Schiebel, B. Hermann, and E. Bodden, “Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++,” 2021.","apa":"Schubert, P., Sattler, F., Schiebel, F. B., Hermann, B., &#38; Bodden, E. (2021). Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++. <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>.","short":"P. Schubert, F. Sattler, F.B. Schiebel, B. Hermann, E. Bodden, in: 2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM), 2021.","chicago":"Schubert, Philipp, Florian Sattler, Fabian Benedikt Schiebel, Ben Hermann, and Eric Bodden. “Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++.” In <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, 2021."},"publication":"2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)","project":[{"name":"SFB 901 - B4: SFB 901 - Subproject B4","_id":"12"},{"name":"SFB 901 - B: SFB 901 - Project Area B","_id":"3"},{"_id":"1","name":"SFB 901: SFB 901: On-The-Fly Computing - Individualisierte IT-Dienstleistungen in dynamischen Märkten "}],"date_created":"2021-10-18T12:50:35Z","department":[{"_id":"76"}],"type":"conference"},{"publication":"Journal of Systems and Software","citation":{"apa":"Geismann, J., &#38; Bodden, E. (2020). A systematic literature review of model-driven security engineering for cyber–physical systems. <i>Journal of Systems and Software</i>, <i>169</i>, 110697. <a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>","ieee":"J. Geismann and E. Bodden, “A systematic literature review of model-driven security engineering for cyber–physical systems,” <i>Journal of Systems and Software</i>, vol. 169, p. 110697, 2020, doi: <a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>.","chicago":"Geismann, Johannes, and Eric Bodden. “A Systematic Literature Review of Model-Driven Security Engineering for Cyber–Physical Systems.” <i>Journal of Systems and Software</i> 169 (2020): 110697. <a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>.","short":"J. Geismann, E. Bodden, Journal of Systems and Software 169 (2020) 110697.","mla":"Geismann, Johannes, and Eric Bodden. “A Systematic Literature Review of Model-Driven Security Engineering for Cyber–Physical Systems.” <i>Journal of Systems and Software</i>, vol. 169, 2020, p. 110697, doi:<a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>.","ama":"Geismann J, Bodden E. A systematic literature review of model-driven security engineering for cyber–physical systems. <i>Journal of Systems and Software</i>. 2020;169:110697. doi:<a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>","bibtex":"@article{Geismann_Bodden_2020, title={A systematic literature review of model-driven security engineering for cyber–physical systems}, volume={169}, DOI={<a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>}, journal={Journal of Systems and Software}, author={Geismann, Johannes and Bodden, Eric}, year={2020}, pages={110697} }"},"type":"journal_article","department":[{"_id":"76"}],"date_created":"2020-11-26T08:32:56Z","date_updated":"2022-01-06T06:54:29Z","intvolume":"       169","title":"A systematic literature review of model-driven security engineering for cyber–physical systems","year":"2020","status":"public","author":[{"last_name":"Geismann","first_name":"Johannes","orcid":"https://orcid.org/0000-0003-2015-2047","full_name":"Geismann, Johannes","id":"20063"},{"full_name":"Bodden, Eric","orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","id":"59256"}],"publication_identifier":{"issn":["0164-1212"]},"user_id":"5786","doi":"https://doi.org/10.1016/j.jss.2020.110697","volume":169,"page":"110697","_id":"20507","language":[{"iso":"eng"}]},{"citation":{"mla":"Fischer, Andreas, et al. “PASAPTO: Policy-Aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage.” <i>2020 IEEE Computer Security Foundations Symposium (CSF)</i>, 2020.","bibtex":"@inproceedings{Fischer_Janneck_Kussmaul_Krätzschmar_Kerschbaum_Bodden_2020, title={PASAPTO: Policy-aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage}, booktitle={2020 IEEE Computer Security Foundations Symposium (CSF)}, author={Fischer, Andreas and Janneck, Jonas and Kussmaul, Jörn and Krätzschmar, Nikolas and Kerschbaum, Florian and Bodden, Eric}, year={2020} }","ama":"Fischer A, Janneck J, Kussmaul J, Krätzschmar N, Kerschbaum F, Bodden E. PASAPTO: Policy-aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage. In: <i>2020 IEEE Computer Security Foundations Symposium (CSF)</i>. ; 2020.","ieee":"A. Fischer, J. Janneck, J. Kussmaul, N. Krätzschmar, F. Kerschbaum, and E. Bodden, “PASAPTO: Policy-aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage,” 2020.","apa":"Fischer, A., Janneck, J., Kussmaul, J., Krätzschmar, N., Kerschbaum, F., &#38; Bodden, E. (2020). PASAPTO: Policy-aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage. <i>2020 IEEE Computer Security Foundations Symposium (CSF)</i>.","short":"A. Fischer, J. Janneck, J. Kussmaul, N. Krätzschmar, F. Kerschbaum, E. Bodden, in: 2020 IEEE Computer Security Foundations Symposium (CSF), 2020.","chicago":"Fischer, Andreas, Jonas Janneck, Jörn Kussmaul, Nikolas Krätzschmar, Florian Kerschbaum, and Eric Bodden. “PASAPTO: Policy-Aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage.” In <i>2020 IEEE Computer Security Foundations Symposium (CSF)</i>, 2020."},"publication":"2020 IEEE Computer Security Foundations Symposium (CSF)","date_created":"2020-11-26T08:40:08Z","department":[{"_id":"76"}],"type":"conference","author":[{"full_name":"Fischer, Andreas","last_name":"Fischer","first_name":"Andreas"},{"full_name":"Janneck, Jonas","last_name":"Janneck","first_name":"Jonas"},{"last_name":"Kussmaul","first_name":"Jörn","full_name":"Kussmaul, Jörn"},{"last_name":"Krätzschmar","first_name":"Nikolas","full_name":"Krätzschmar, Nikolas"},{"full_name":"Kerschbaum, Florian","first_name":"Florian","last_name":"Kerschbaum"},{"last_name":"Bodden","first_name":"Eric","orcid":"0000-0003-3470-3647","full_name":"Bodden, Eric","id":"59256"}],"status":"public","year":"2020","title":"PASAPTO: Policy-aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage","date_updated":"2022-01-06T06:54:29Z","_id":"20509","language":[{"iso":"eng"}],"main_file_link":[{"url":"http://www.bodden.de/pubs/fjk+20pasapto.pdf"}],"user_id":"5786"},{"user_id":"5786","main_file_link":[{"url":"http://www.bodden.de/pubs/ffk+20computation.pdf"}],"_id":"20511","language":[{"iso":"eng"}],"date_updated":"2022-01-06T06:54:29Z","title":"Computation on Encrypted Data using Dataflow Authentication","year":"2020","status":"public","author":[{"full_name":"Fischer, Andreas","last_name":"Fischer","first_name":"Andreas"},{"full_name":"Fuhry, Benny","first_name":"Benny","last_name":"Fuhry"},{"first_name":"Florian","last_name":"Kerschbaum","full_name":"Kerschbaum, Florian"},{"id":"59256","first_name":"Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647","full_name":"Bodden, Eric"}],"type":"conference","department":[{"_id":"76"}],"date_created":"2020-11-26T08:50:59Z","publication":"Privacy Enhancing Technologies Symposium (PETS/PoPETS)","citation":{"ama":"Fischer A, Fuhry B, Kerschbaum F, Bodden E. Computation on Encrypted Data using Dataflow Authentication. In: <i>Privacy Enhancing Technologies Symposium (PETS/PoPETS)</i>. ; 2020.","bibtex":"@inproceedings{Fischer_Fuhry_Kerschbaum_Bodden_2020, title={Computation on Encrypted Data using Dataflow Authentication}, booktitle={Privacy Enhancing Technologies Symposium (PETS/PoPETS)}, author={Fischer, Andreas and Fuhry, Benny and Kerschbaum, Florian and Bodden, Eric}, year={2020} }","mla":"Fischer, Andreas, et al. “Computation on Encrypted Data Using Dataflow Authentication.” <i>Privacy Enhancing Technologies Symposium (PETS/PoPETS)</i>, 2020.","chicago":"Fischer, Andreas, Benny Fuhry, Florian Kerschbaum, and Eric Bodden. “Computation on Encrypted Data Using Dataflow Authentication.” In <i>Privacy Enhancing Technologies Symposium (PETS/PoPETS)</i>, 2020.","short":"A. Fischer, B. Fuhry, F. Kerschbaum, E. Bodden, in: Privacy Enhancing Technologies Symposium (PETS/PoPETS), 2020.","apa":"Fischer, A., Fuhry, B., Kerschbaum, F., &#38; Bodden, E. (2020). Computation on Encrypted Data using Dataflow Authentication. <i>Privacy Enhancing Technologies Symposium (PETS/PoPETS)</i>.","ieee":"A. Fischer, B. Fuhry, F. Kerschbaum, and E. Bodden, “Computation on Encrypted Data using Dataflow Authentication,” 2020."}},{"publication":"International Symposium on Code Generation and Optimization (CGO)","citation":{"apa":"Krüger, S., Ali, K., &#38; Bodden, E. (2020). CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs. <i>International Symposium on Code Generation and Optimization (CGO)</i>, 185–198.","ieee":"S. Krüger, K. Ali, and E. Bodden, “CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs,” in <i>International Symposium on Code Generation and Optimization (CGO)</i>, 2020, pp. 185–198.","short":"S. Krüger, K. Ali, E. Bodden, in: International Symposium on Code Generation and Optimization (CGO), 2020, pp. 185–198.","chicago":"Krüger, Stefan, Karim Ali, and Eric Bodden. “CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs.” In <i>International Symposium on Code Generation and Optimization (CGO)</i>, 185–98, 2020.","mla":"Krüger, Stefan, et al. “CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs.” <i>International Symposium on Code Generation and Optimization (CGO)</i>, 2020, pp. 185–98.","ama":"Krüger S, Ali K, Bodden E. CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs. In: <i>International Symposium on Code Generation and Optimization (CGO)</i>. ; 2020:185-198.","bibtex":"@inproceedings{Krüger_Ali_Bodden_2020, title={CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs}, booktitle={International Symposium on Code Generation and Optimization (CGO)}, author={Krüger, Stefan and Ali, Karim and Bodden, Eric}, year={2020}, pages={185–198} }"},"related_material":{"link":[{"relation":"confirmation","url":"http://www.bodden.de/pubs/krueger20cognicryptgen.pdf"}]},"date_created":"2020-11-26T08:51:01Z","type":"conference","department":[{"_id":"76"}],"year":"2020","title":"CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs","status":"public","author":[{"first_name":"Stefan","last_name":"Krüger","full_name":"Krüger, Stefan"},{"last_name":"Ali","first_name":"Karim","full_name":"Ali, Karim"},{"full_name":"Bodden, Eric","first_name":"Eric","last_name":"Bodden"}],"date_updated":"2022-01-06T06:54:29Z","page":"185-198","_id":"20512","language":[{"iso":"eng"}],"user_id":"5786"},{"user_id":"5786","_id":"20513","publisher":"Universitaetsbibliothek Paderborn","language":[{"iso":"eng"}],"main_file_link":[{"url":"https://digital.ub.uni-paderborn.de/hs/document/preview/3500836"}],"date_updated":"2022-01-06T06:54:29Z","author":[{"full_name":"Krüger, Stefan","first_name":"Stefan","last_name":"Krüger"}],"title":"CogniCrypt -- The Secure Integration of Cryptographic Software","year":"2020","status":"public","department":[{"_id":"76"}],"type":"dissertation","date_created":"2020-11-26T09:02:19Z","abstract":[{"lang":"ger","text":"Frühere Studien haben empirisch offenbart, dass Fehlbenutzungen von kryptographischen APIs in Softwareanwendungen weitverbreitet sind. Dies geschieht vor allem, weil Software-Entwickler_innen aufgrund schlechten API-Designs und fehlenden Kryptographiewissens Probleme bekommen, wenn sie versuchen kryptographische Features zu implementieren. Die Literatur liefert mehrere Ansätze und Vorschläge diese Probleme zu lösen, aber alle scheitern schlussendlich auf die eine oder andere Weise daran die Anforderungen der Entwickler_innenzu erfüllen. Das Resultat ist eine insgesamt lückenhafte Landschaft verschiedener nur wenigkomplementärer Ansätze.In dieser Arbeit adressieren wir das Problem kryptographischer Fehlbenutzungen systematischer durch CogniCrypt. CogniCrypt integriert verschiedene Arten von Tool Supportin einen gemeinsamen Ansatz, der Entwickler_innen davon befreit wissen zu müssen, wie diese APIs benutzt werden müssen. Zentral für unseren Ansatz ist CrySL, eine Beschreibungssprache,die die kognitive Lücke zwischen Kryptographie-Expert_innen und Software-Entwickler_innenüberbrückt. CrySL ermöglicht es Kryptographie-Expert_innen zu spezifizeren, wie die APIs,die sie bereitstellen, richtig benutzt werden. Wir haben einen Compiler für CrySL implementiert, der es erlaubt auf CrySL-Spezifikationen aufbauenden Tool Support zu entwickeln. Wir haben weiterhin die statische Analyse CogniCrypt_SAST und den Code-Generator CogniCrypt_GEN entwickelt. Schlussendlich haben wir CogniCrypt prototypisch implementiert und diesen Prototyp in einem kontrollierten Experiment evaluiert.\r\n"}],"citation":{"short":"S. Krüger, CogniCrypt -- The Secure Integration of Cryptographic Software, Universitaetsbibliothek Paderborn, 2020.","chicago":"Krüger, Stefan. <i>CogniCrypt -- The Secure Integration of Cryptographic Software</i>. Universitaetsbibliothek Paderborn, 2020.","ieee":"S. Krüger, <i>CogniCrypt -- The Secure Integration of Cryptographic Software</i>. Universitaetsbibliothek Paderborn, 2020.","apa":"Krüger, S. (2020). <i>CogniCrypt -- The Secure Integration of Cryptographic Software</i>. Universitaetsbibliothek Paderborn.","bibtex":"@book{Krüger_2020, title={CogniCrypt -- The Secure Integration of Cryptographic Software}, publisher={Universitaetsbibliothek Paderborn}, author={Krüger, Stefan}, year={2020} }","ama":"Krüger S. <i>CogniCrypt -- The Secure Integration of Cryptographic Software</i>. Universitaetsbibliothek Paderborn; 2020.","mla":"Krüger, Stefan. <i>CogniCrypt -- The Secure Integration of Cryptographic Software</i>. Universitaetsbibliothek Paderborn, 2020."},"supervisor":[{"id":"59256","full_name":"Bodden, Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","first_name":"Eric"}]},{"year":"2020","title":"Scenario-based Specification of Security Protocols and Transformation to Security Model Checkers","status":"public","author":[{"last_name":"Koch","first_name":"Thorsten","full_name":"Koch, Thorsten","id":"13616"},{"last_name":"Dziwok","first_name":"Stefan","orcid":"http://orcid.org/0000-0002-8679-6673","full_name":"Dziwok, Stefan","id":"3901"},{"id":"3875","full_name":"Holtmann, Jörg","orcid":"0000-0001-6141-4571","last_name":"Holtmann","first_name":"Jörg"},{"orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","full_name":"Bodden, Eric","id":"59256"}],"date_updated":"2022-01-06T06:54:29Z","_id":"20518","language":[{"iso":"eng"}],"publisher":"ACM","doi":"10.1145/3365438.3410946","user_id":"5786","publication":"ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)","citation":{"mla":"Koch, Thorsten, et al. “Scenario-Based Specification of Security Protocols and Transformation to Security Model Checkers.” <i>ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)</i>, ACM, 2020, doi:<a href=\"https://doi.org/10.1145/3365438.3410946\">10.1145/3365438.3410946</a>.","ama":"Koch T, Dziwok S, Holtmann J, Bodden E. Scenario-based Specification of Security Protocols and Transformation to Security Model Checkers. In: <i>ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)</i>. ACM; 2020. doi:<a href=\"https://doi.org/10.1145/3365438.3410946\">10.1145/3365438.3410946</a>","bibtex":"@inproceedings{Koch_Dziwok_Holtmann_Bodden_2020, title={Scenario-based Specification of Security Protocols and Transformation to Security Model Checkers}, DOI={<a href=\"https://doi.org/10.1145/3365438.3410946\">10.1145/3365438.3410946</a>}, booktitle={ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)}, publisher={ACM}, author={Koch, Thorsten and Dziwok, Stefan and Holtmann, Jörg and Bodden, Eric}, year={2020} }","apa":"Koch, T., Dziwok, S., Holtmann, J., &#38; Bodden, E. (2020). Scenario-based Specification of Security Protocols and Transformation to Security Model Checkers. <i>ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)</i>. <a href=\"https://doi.org/10.1145/3365438.3410946\">https://doi.org/10.1145/3365438.3410946</a>","ieee":"T. Koch, S. Dziwok, J. Holtmann, and E. Bodden, “Scenario-based Specification of Security Protocols and Transformation to Security Model Checkers,” 2020, doi: <a href=\"https://doi.org/10.1145/3365438.3410946\">10.1145/3365438.3410946</a>.","chicago":"Koch, Thorsten, Stefan Dziwok, Jörg Holtmann, and Eric Bodden. “Scenario-Based Specification of Security Protocols and Transformation to Security Model Checkers.” In <i>ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)</i>. ACM, 2020. <a href=\"https://doi.org/10.1145/3365438.3410946\">https://doi.org/10.1145/3365438.3410946</a>.","short":"T. Koch, S. Dziwok, J. Holtmann, E. Bodden, in: ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20), ACM, 2020."},"date_created":"2020-11-26T10:19:54Z","type":"conference","department":[{"_id":"76"},{"_id":"241"},{"_id":"662"}]},{"citation":{"ama":"Gerking C. <i>Model-Driven Information Flow Security Engineering for Cyber-Physical Systems</i>. Paderborn University; 2020. doi:<a href=\"https://doi.org/10.17619/UNIPB/1-1033\">10.17619/UNIPB/1-1033</a>","bibtex":"@book{Gerking_2020, title={Model-Driven Information Flow Security Engineering for Cyber-Physical Systems}, DOI={<a href=\"https://doi.org/10.17619/UNIPB/1-1033\">10.17619/UNIPB/1-1033</a>}, publisher={Paderborn University}, author={Gerking, Christopher}, year={2020} }","mla":"Gerking, Christopher. <i>Model-Driven Information Flow Security Engineering for Cyber-Physical Systems</i>. Paderborn University, 2020, doi:<a href=\"https://doi.org/10.17619/UNIPB/1-1033\">10.17619/UNIPB/1-1033</a>.","chicago":"Gerking, Christopher. <i>Model-Driven Information Flow Security Engineering for Cyber-Physical Systems</i>. Paderborn University, 2020. <a href=\"https://doi.org/10.17619/UNIPB/1-1033\">https://doi.org/10.17619/UNIPB/1-1033</a>.","short":"C. Gerking, Model-Driven Information Flow Security Engineering for Cyber-Physical Systems, Paderborn University, 2020.","apa":"Gerking, C. (2020). <i>Model-Driven Information Flow Security Engineering for Cyber-Physical Systems</i>. Paderborn University. <a href=\"https://doi.org/10.17619/UNIPB/1-1033\">https://doi.org/10.17619/UNIPB/1-1033</a>","ieee":"C. Gerking, <i>Model-Driven Information Flow Security Engineering for Cyber-Physical Systems</i>. Paderborn University, 2020."},"supervisor":[{"full_name":"Bodden, Eric","orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","id":"59256"}],"date_created":"2020-11-26T10:37:17Z","type":"dissertation","department":[{"_id":"76"}],"year":"2020","status":"public","title":"Model-Driven Information Flow Security Engineering for Cyber-Physical Systems","author":[{"first_name":"Christopher","last_name":"Gerking","full_name":"Gerking, Christopher"}],"date_updated":"2022-01-06T06:54:29Z","language":[{"iso":"eng"}],"_id":"20521","publisher":"Paderborn University","user_id":"5786","doi":"10.17619/UNIPB/1-1033"},{"project":[{"_id":"1","name":"SFB 901"},{"_id":"3","name":"SFB 901 - Project Area B"},{"_id":"12","name":"SFB 901 - Subproject B4"}],"file_date_updated":"2020-12-14T07:39:07Z","citation":{"ama":"Schubert P, Bodden E, Hermann B. <i>Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries</i>.; 2020.","bibtex":"@book{Schubert_Bodden_Hermann_2020, title={Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries}, author={Schubert, Philipp and Bodden, Eric and Hermann, Ben}, year={2020} }","mla":"Schubert, Philipp, et al. <i>Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries</i>. 2020.","chicago":"Schubert, Philipp, Eric Bodden, and Ben Hermann. <i>Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries</i>, 2020.","short":"P. Schubert, E. Bodden, B. Hermann, Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries, 2020.","apa":"Schubert, P., Bodden, E., &#38; Hermann, B. (2020). <i>Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries</i>.","ieee":"P. Schubert, E. Bodden, and B. Hermann, <i>Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries</i>. 2020."},"type":"report","department":[{"_id":"76"}],"file":[{"creator":"pdschbrt","date_created":"2020-12-14T07:39:07Z","relation":"main_file","date_updated":"2020-12-14T07:39:07Z","file_name":"main.pdf","access_level":"closed","file_size":683576,"file_id":"20713","success":1,"content_type":"application/pdf"}],"date_created":"2020-12-14T07:44:11Z","date_updated":"2022-01-06T06:54:34Z","has_accepted_license":"1","status":"public","title":"Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries","year":"2020","author":[{"id":"60543","orcid":"0000-0002-8674-1859","last_name":"Schubert","first_name":"Philipp","full_name":"Schubert, Philipp"},{"full_name":"Bodden, Eric","first_name":"Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647","id":"59256"},{"id":"66173","orcid":"0000-0001-9848-2017","last_name":"Hermann","first_name":"Ben","full_name":"Hermann, Ben"}],"ddc":["000"],"user_id":"477","language":[{"iso":"eng"}],"_id":"20712"}]
