@inproceedings{20529,
  author       = {{Nachtigall, Marcus and Nguyen Quang Do, Lisa and Bodden, Eric}},
  booktitle    = {{1st International Workshop on Explainable Software (EXPLAIN) at ASE}},
  title        = {{{Explaining Static Analysis -- A Perspective}}},
  year         = {{2019}},
}

@inproceedings{20531,
  author       = {{Luo, Linghui and Bodden, Eric and Späth, Johannes}},
  booktitle    = {{IEEE/ACM International Conference on Automated Software Engineering (ASE 2019)}},
  title        = {{{A Qualitative Analysis of Android Taint-Analysis Results}}},
  year         = {{2019}},
}

@inproceedings{20532,
  author       = {{Piskachev, Goran and Nguyen Quang Do, Lisa and Johnson, Oshando and Bodden, Eric}},
  booktitle    = {{IEEE/ACM International Conference on Automated Software Engineering (ASE 2019), Tool Demo Track}},
  title        = {{{SWAN_ASSIST: Semi-Automated Detection of Code-Specific, Security-Relevant Methods}}},
  year         = {{2019}},
}

@article{20533,
  author       = {{Krüger, Stefan and Späth, Johannes and Ali, Karim and Bodden, Eric and Mezini, Mira}},
  issn         = {{2326-3881}},
  journal      = {{IEEE Transactions on Software Engineering}},
  keywords     = {{Java, Encryption, Static analysis, Tools, Ciphers, Semantics, cryptography, domain-specific language, static analysis}},
  pages        = {{1--1}},
  title        = {{{CrySL: An Extensible Approach to Validating the Correct Usage of Cryptographic APIs}}},
  doi          = {{10.1109/TSE.2019.2948910}},
  year         = {{2019}},
}

@inproceedings{20534,
  author       = {{Piskachev, Goran and Nguyen Quang Do, Lisa and Bodden, Eric}},
  booktitle    = {{ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA)}},
  title        = {{{Codebase-Adaptive Detection of Security-Relevant Methods}}},
  year         = {{2019}},
}

@inproceedings{20535,
  author       = {{Luo, Linghui and Dolby, Julian and Bodden, Eric}},
  booktitle    = {{European Conference on Object-Oriented Programming (ECOOP)}},
  title        = {{{MagpieBridge: A General Approach to Integrating Static Analyses into IDEs and Editors}}},
  year         = {{2019}},
}

@phdthesis{20536,
  author       = {{Späth, Johannes}},
  publisher    = {{Universität Paderborn}},
  title        = {{{Synchronized Pushdown Systems for Pointer and Data-Flow Analysis}}},
  year         = {{2019}},
}

@techreport{20537,
  author       = {{Piskachev, Goran and Nguyen, Lisa and Bodden, Eric}},
  title        = {{{Codebase-Adaptive Detection of Security-Relevant Methods}}},
  year         = {{2019}},
}

@inproceedings{20538,
  author       = {{Albert Gorski Iii, Sigmund and Andow, Benjamin and Nadkarni, Adwait and Manandhar, Sunil and Enck, William and Bodden, Eric and Bartel, Alexandre}},
  booktitle    = {{ACM Conference on Data and Application Security and Privacy (CODASPY 2019)}},
  keywords     = {{ITSECWEBSITE, CROSSING}},
  title        = {{{ACMiner: Extraction and Analysis of Authorization Checks in Android's Middleware}}},
  year         = {{2019}},
}

@article{20539,
  author       = {{Späth, Johannes and Ali, Karim and Bodden, Eric}},
  issn         = {{2475-1421}},
  journal      = {{Proceedings of the ACM SIGPLAN Symposium on Principles of Programming Languages}},
  keywords     = {{ATTRACT, ITSECWEBSITE, CROSSING}},
  number       = {{POPL}},
  pages        = {{48:1--48:29}},
  publisher    = {{ACM}},
  title        = {{{Context-, Flow-, and Field-sensitive Data-flow Analysis Using Synchronized Pushdown Systems}}},
  doi          = {{10.1145/3290361}},
  volume       = {{3}},
  year         = {{2019}},
}

@inproceedings{20759,
  author       = {{Gerking, Christopher and Schubert, David}},
  booktitle    = {{International Conference on Software Architecture (ICSA 2019)}},
  title        = {{{Component-Based Refinement and Verification of Information-Flow Security Policies for Cyber-Physical Microservice Architectures}}},
  year         = {{2019}},
}

@inproceedings{23378,
  author       = {{Piskachev, Goran and Do, Lisa Nguyen Quang and Bodden, Eric}},
  booktitle    = {{Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis}},
  title        = {{{Codebase-adaptive detection of security-relevant methods}}},
  doi          = {{10.1145/3293882.3330556}},
  year         = {{2019}},
}

@misc{7628,
  author       = {{Selbach, Nils}},
  publisher    = {{Universität Paderborn}},
  title        = {{{Modeling Crypto API usages in OpenSSL's EVP library}}},
  year         = {{2019}},
}

@article{14896,
  author       = {{Dann, Andreas and Hermann, Ben and Bodden, Eric}},
  issn         = {{0098-5589}},
  journal      = {{IEEE Transactions on Software Engineering}},
  pages        = {{1--1}},
  title        = {{{ModGuard: Identifying Integrity &Confidentiality Violations in Java Modules}}},
  doi          = {{10.1109/tse.2019.2931331}},
  year         = {{2019}},
}

@inproceedings{14897,
  author       = {{Dann, Andreas and Hermann, Ben and Bodden, Eric}},
  booktitle    = {{Proceedings of the 8th ACM SIGPLAN International Workshop on State Of the Art in Program Analysis  - SOAP 2019}},
  isbn         = {{9781450367202}},
  title        = {{{SootDiff: bytecode comparison across different Java compilers}}},
  doi          = {{10.1145/3315568.3329966}},
  year         = {{2019}},
}

@inproceedings{14899,
  author       = {{Kruger, Stefan and Hermann, Ben}},
  booktitle    = {{2019 IEEE/ACM 2nd International Workshop on Gender Equality in Software Engineering (GE)}},
  isbn         = {{9781728122458}},
  title        = {{{Can an Online Service Predict Gender? On the State-of-the-Art in Gender Identification from Texts}}},
  doi          = {{10.1109/ge.2019.00012}},
  year         = {{2019}},
}

@inproceedings{7626,
  author       = {{Schubert, Philipp and Hermann, Ben and Bodden, Eric}},
  booktitle    = {{Proceedings of the 25th International Conference on Tools and Algorithms for the Construction and Analysis of Systems (TACAS 2019), Held as Part of the European Joint Conferences on Theory and Practice of Software (ETAPS 2019)}},
  location     = {{Prague, Czech Republic}},
  pages        = {{393--410}},
  title        = {{{PhASAR: An Inter-Procedural Static Analysis Framework for C/C++}}},
  doi          = {{10.1007/978-3-030-17465-1_22}},
  volume       = {{II}},
  year         = {{2019}},
}

@inproceedings{14898,
  author       = {{Schubert, Philipp and Leer, Richard and Hermann, Ben and Bodden, Eric}},
  booktitle    = {{Proceedings of the 8th ACM SIGPLAN International Workshop on State Of the Art in Program Analysis  - SOAP 2019}},
  isbn         = {{9781450367202}},
  title        = {{{Know your analysis: how instrumentation aids understanding static analysis}}},
  doi          = {{10.1145/3315568.3329965}},
  year         = {{2019}},
}

@unpublished{2711,
  abstract     = {{In recent years, researchers have developed a number of tools to conduct
taint analysis of Android applications. While all the respective papers aim at
providing a thorough empirical evaluation, comparability is hindered by varying
or unclear evaluation targets. Sometimes, the apps used for evaluation are not
precisely described. In other cases, authors use an established benchmark but
cover it only partially. In yet other cases, the evaluations differ in terms of
the data leaks searched for, or lack a ground truth to compare against. All
those limitations make it impossible to truly compare the tools based on those
published evaluations.
  We thus present ReproDroid, a framework allowing the accurate comparison of
Android taint analysis tools. ReproDroid supports researchers in inferring the
ground truth for data leaks in apps, in automatically applying tools to
benchmarks, and in evaluating the obtained results. We use ReproDroid to
comparatively evaluate on equal grounds the six prominent taint analysis tools
Amandroid, DIALDroid, DidFail, DroidSafe, FlowDroid and IccTA. The results are
largely positive although four tools violate some promises concerning features
and accuracy. Finally, we contribute to the area of unbiased benchmarking with
a new and improved version of the open test suite DroidBench.}},
  author       = {{Pauck, Felix and Bodden, Eric and Wehrheim, Heike}},
  booktitle    = {{arXiv:1804.02903}},
  title        = {{{Do Android Taint Analysis Tools Keep their Promises?}}},
  year         = {{2018}},
}

@inproceedings{20530,
  author       = {{Bodden, Eric and Nguyen Quang Do, Lisa}},
  booktitle    = {{Software Engineering und Software Management 2018, Fachtagung des GI-Fachbereichs Softwaretechnik, {SE} 2018, 5.-9. M{\"{a}}rz 2018, Ulm, Germany.}},
  isbn         = {{978-3-88579-673-2}},
  pages        = {{205--208}},
  title        = {{{Explainable Static Analysis}}},
  year         = {{2018}},
}

