[{"publication_status":"published","date_updated":"2025-11-11T14:28:46Z","author":[{"id":"26886","last_name":"Dann","first_name":"Andreas Peter","full_name":"Dann, Andreas Peter"},{"full_name":"Plate, Henrik","first_name":"Henrik","last_name":"Plate"},{"full_name":"Hermann, Ben","orcid":"0000-0001-9848-2017","first_name":"Ben","last_name":"Hermann","id":"66173"},{"full_name":"Ponta, Serena Elisa","first_name":"Serena Elisa","last_name":"Ponta"},{"first_name":"Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647","full_name":"Bodden, Eric","id":"59256"}],"publication_identifier":{"issn":["0098-5589","1939-3520","2326-3881"]},"title":"Identifying Challenges for OSS Vulnerability Scanners - A Study &amp; Test Suite","status":"public","year":"2021","user_id":"477","doi":"10.1109/tse.2021.3101739","_id":"31132","language":[{"iso":"eng"}],"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","page":"1-1","project":[{"_id":"107","name":"Reaktor: SFB 901 - Automatisierte Risikoanalyse in Bezug auf Open-Source-Abhängigkeiten (Hektor) (Transferproject T3)"},{"name":"SFB 901: On-The-Fly Computing - Individualisierte IT-Dienstleistungen in dynamischen Märkten","_id":"1"},{"name":"SFB 901; Projektbereich T: Transferprojekte des Sonderforschungsbereichs","_id":"82"},{"_id":"107","name":"SFB 901; TP T3: Automatisierte Risikoanalyse in Bezug auf Open-Source-Abhängigkeiten (Hektor)"}],"citation":{"chicago":"Dann, Andreas Peter, Henrik Plate, Ben Hermann, Serena Elisa Ponta, and Eric Bodden. “Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite.” <i>IEEE Transactions on Software Engineering</i>, 2021, 1–1. <a href=\"https://doi.org/10.1109/tse.2021.3101739\">https://doi.org/10.1109/tse.2021.3101739</a>.","short":"A.P. Dann, H. Plate, B. Hermann, S.E. Ponta, E. Bodden, IEEE Transactions on Software Engineering (2021) 1–1.","ieee":"A. P. Dann, H. Plate, B. Hermann, S. E. Ponta, and E. Bodden, “Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite,” <i>IEEE Transactions on Software Engineering</i>, pp. 1–1, 2021, doi: <a href=\"https://doi.org/10.1109/tse.2021.3101739\">10.1109/tse.2021.3101739</a>.","apa":"Dann, A. P., Plate, H., Hermann, B., Ponta, S. E., &#38; Bodden, E. (2021). Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite. <i>IEEE Transactions on Software Engineering</i>, 1–1. <a href=\"https://doi.org/10.1109/tse.2021.3101739\">https://doi.org/10.1109/tse.2021.3101739</a>","bibtex":"@article{Dann_Plate_Hermann_Ponta_Bodden_2021, title={Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite}, DOI={<a href=\"https://doi.org/10.1109/tse.2021.3101739\">10.1109/tse.2021.3101739</a>}, journal={IEEE Transactions on Software Engineering}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Dann, Andreas Peter and Plate, Henrik and Hermann, Ben and Ponta, Serena Elisa and Bodden, Eric}, year={2021}, pages={1–1} }","ama":"Dann AP, Plate H, Hermann B, Ponta SE, Bodden E. Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite. <i>IEEE Transactions on Software Engineering</i>. Published online 2021:1-1. doi:<a href=\"https://doi.org/10.1109/tse.2021.3101739\">10.1109/tse.2021.3101739</a>","mla":"Dann, Andreas Peter, et al. “Identifying Challenges for OSS Vulnerability Scanners - A Study &#38;amp; Test Suite.” <i>IEEE Transactions on Software Engineering</i>, Institute of Electrical and Electronics Engineers (IEEE), 2021, pp. 1–1, doi:<a href=\"https://doi.org/10.1109/tse.2021.3101739\">10.1109/tse.2021.3101739</a>."},"publication":"IEEE Transactions on Software Engineering","department":[{"_id":"76"}],"keyword":["Software"],"type":"journal_article","date_created":"2022-05-09T13:02:35Z"},{"language":[{"iso":"eng"}],"_id":"26405","user_id":"15249","author":[{"id":"60543","orcid":"0000-0002-8674-1859","first_name":"Philipp","last_name":"Schubert","full_name":"Schubert, Philipp"},{"full_name":"Sattler, Florian","last_name":"Sattler","first_name":"Florian"},{"first_name":"Fabian Benedikt","last_name":"Schiebel","orcid":"0009-0008-6867-9802","full_name":"Schiebel, Fabian Benedikt","id":"55745"},{"orcid":"0000-0001-9848-2017","last_name":"Hermann","first_name":"Ben","full_name":"Hermann, Ben","id":"66173"},{"id":"59256","full_name":"Bodden, Eric","first_name":"Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden"}],"year":"2021","status":"public","title":"Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++","date_updated":"2025-12-04T10:43:01Z","date_created":"2021-10-18T12:50:35Z","department":[{"_id":"76"}],"type":"conference","citation":{"chicago":"Schubert, Philipp, Florian Sattler, Fabian Benedikt Schiebel, Ben Hermann, and Eric Bodden. “Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++.” In <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, 2021.","short":"P. Schubert, F. Sattler, F.B. Schiebel, B. Hermann, E. Bodden, in: 2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM), 2021.","ieee":"P. Schubert, F. Sattler, F. B. Schiebel, B. Hermann, and E. Bodden, “Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++,” 2021.","apa":"Schubert, P., Sattler, F., Schiebel, F. B., Hermann, B., &#38; Bodden, E. (2021). Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++. <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>.","bibtex":"@inproceedings{Schubert_Sattler_Schiebel_Hermann_Bodden_2021, title={Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++}, booktitle={2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)}, author={Schubert, Philipp and Sattler, Florian and Schiebel, Fabian Benedikt and Hermann, Ben and Bodden, Eric}, year={2021} }","ama":"Schubert P, Sattler F, Schiebel FB, Hermann B, Bodden E. Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++. In: <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>. ; 2021.","mla":"Schubert, Philipp, et al. “Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++.” <i>2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)</i>, 2021."},"publication":"2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)","project":[{"_id":"12","name":"SFB 901 - B4: SFB 901 - Subproject B4"},{"_id":"3","name":"SFB 901 - B: SFB 901 - Project Area B"},{"_id":"1","name":"SFB 901: SFB 901: On-The-Fly Computing - Individualisierte IT-Dienstleistungen in dynamischen Märkten "}]},{"date_updated":"2022-01-06T06:54:29Z","intvolume":"       169","title":"A systematic literature review of model-driven security engineering for cyber–physical systems","status":"public","year":"2020","author":[{"orcid":"https://orcid.org/0000-0003-2015-2047","last_name":"Geismann","first_name":"Johannes","full_name":"Geismann, Johannes","id":"20063"},{"id":"59256","orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","full_name":"Bodden, Eric"}],"publication_identifier":{"issn":["0164-1212"]},"doi":"https://doi.org/10.1016/j.jss.2020.110697","user_id":"5786","volume":169,"page":"110697","language":[{"iso":"eng"}],"_id":"20507","publication":"Journal of Systems and Software","citation":{"mla":"Geismann, Johannes, and Eric Bodden. “A Systematic Literature Review of Model-Driven Security Engineering for Cyber–Physical Systems.” <i>Journal of Systems and Software</i>, vol. 169, 2020, p. 110697, doi:<a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>.","bibtex":"@article{Geismann_Bodden_2020, title={A systematic literature review of model-driven security engineering for cyber–physical systems}, volume={169}, DOI={<a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>}, journal={Journal of Systems and Software}, author={Geismann, Johannes and Bodden, Eric}, year={2020}, pages={110697} }","ama":"Geismann J, Bodden E. A systematic literature review of model-driven security engineering for cyber–physical systems. <i>Journal of Systems and Software</i>. 2020;169:110697. doi:<a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>","ieee":"J. Geismann and E. Bodden, “A systematic literature review of model-driven security engineering for cyber–physical systems,” <i>Journal of Systems and Software</i>, vol. 169, p. 110697, 2020, doi: <a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>.","apa":"Geismann, J., &#38; Bodden, E. (2020). A systematic literature review of model-driven security engineering for cyber–physical systems. <i>Journal of Systems and Software</i>, <i>169</i>, 110697. <a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>","short":"J. Geismann, E. Bodden, Journal of Systems and Software 169 (2020) 110697.","chicago":"Geismann, Johannes, and Eric Bodden. “A Systematic Literature Review of Model-Driven Security Engineering for Cyber–Physical Systems.” <i>Journal of Systems and Software</i> 169 (2020): 110697. <a href=\"https://doi.org/10.1016/j.jss.2020.110697\">https://doi.org/10.1016/j.jss.2020.110697</a>."},"type":"journal_article","department":[{"_id":"76"}],"date_created":"2020-11-26T08:32:56Z"},{"main_file_link":[{"url":"http://www.bodden.de/pubs/fjk+20pasapto.pdf"}],"_id":"20509","language":[{"iso":"eng"}],"user_id":"5786","year":"2020","status":"public","title":"PASAPTO: Policy-aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage","author":[{"last_name":"Fischer","first_name":"Andreas","full_name":"Fischer, Andreas"},{"full_name":"Janneck, Jonas","last_name":"Janneck","first_name":"Jonas"},{"full_name":"Kussmaul, Jörn","first_name":"Jörn","last_name":"Kussmaul"},{"last_name":"Krätzschmar","first_name":"Nikolas","full_name":"Krätzschmar, Nikolas"},{"full_name":"Kerschbaum, Florian","first_name":"Florian","last_name":"Kerschbaum"},{"first_name":"Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","full_name":"Bodden, Eric","id":"59256"}],"date_updated":"2022-01-06T06:54:29Z","date_created":"2020-11-26T08:40:08Z","type":"conference","department":[{"_id":"76"}],"publication":"2020 IEEE Computer Security Foundations Symposium (CSF)","citation":{"ama":"Fischer A, Janneck J, Kussmaul J, Krätzschmar N, Kerschbaum F, Bodden E. PASAPTO: Policy-aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage. In: <i>2020 IEEE Computer Security Foundations Symposium (CSF)</i>. ; 2020.","bibtex":"@inproceedings{Fischer_Janneck_Kussmaul_Krätzschmar_Kerschbaum_Bodden_2020, title={PASAPTO: Policy-aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage}, booktitle={2020 IEEE Computer Security Foundations Symposium (CSF)}, author={Fischer, Andreas and Janneck, Jonas and Kussmaul, Jörn and Krätzschmar, Nikolas and Kerschbaum, Florian and Bodden, Eric}, year={2020} }","mla":"Fischer, Andreas, et al. “PASAPTO: Policy-Aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage.” <i>2020 IEEE Computer Security Foundations Symposium (CSF)</i>, 2020.","short":"A. Fischer, J. Janneck, J. Kussmaul, N. Krätzschmar, F. Kerschbaum, E. Bodden, in: 2020 IEEE Computer Security Foundations Symposium (CSF), 2020.","chicago":"Fischer, Andreas, Jonas Janneck, Jörn Kussmaul, Nikolas Krätzschmar, Florian Kerschbaum, and Eric Bodden. “PASAPTO: Policy-Aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage.” In <i>2020 IEEE Computer Security Foundations Symposium (CSF)</i>, 2020.","apa":"Fischer, A., Janneck, J., Kussmaul, J., Krätzschmar, N., Kerschbaum, F., &#38; Bodden, E. (2020). PASAPTO: Policy-aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage. <i>2020 IEEE Computer Security Foundations Symposium (CSF)</i>.","ieee":"A. Fischer, J. Janneck, J. Kussmaul, N. Krätzschmar, F. Kerschbaum, and E. Bodden, “PASAPTO: Policy-aware Security and Performance Trade-off Analysis - Computation on Encrypted Data with Restricted Leakage,” 2020."}},{"type":"conference","department":[{"_id":"76"}],"date_created":"2020-11-26T08:50:59Z","publication":"Privacy Enhancing Technologies Symposium (PETS/PoPETS)","citation":{"apa":"Fischer, A., Fuhry, B., Kerschbaum, F., &#38; Bodden, E. (2020). Computation on Encrypted Data using Dataflow Authentication. <i>Privacy Enhancing Technologies Symposium (PETS/PoPETS)</i>.","ieee":"A. Fischer, B. Fuhry, F. Kerschbaum, and E. Bodden, “Computation on Encrypted Data using Dataflow Authentication,” 2020.","chicago":"Fischer, Andreas, Benny Fuhry, Florian Kerschbaum, and Eric Bodden. “Computation on Encrypted Data Using Dataflow Authentication.” In <i>Privacy Enhancing Technologies Symposium (PETS/PoPETS)</i>, 2020.","short":"A. Fischer, B. Fuhry, F. Kerschbaum, E. Bodden, in: Privacy Enhancing Technologies Symposium (PETS/PoPETS), 2020.","mla":"Fischer, Andreas, et al. “Computation on Encrypted Data Using Dataflow Authentication.” <i>Privacy Enhancing Technologies Symposium (PETS/PoPETS)</i>, 2020.","ama":"Fischer A, Fuhry B, Kerschbaum F, Bodden E. Computation on Encrypted Data using Dataflow Authentication. In: <i>Privacy Enhancing Technologies Symposium (PETS/PoPETS)</i>. ; 2020.","bibtex":"@inproceedings{Fischer_Fuhry_Kerschbaum_Bodden_2020, title={Computation on Encrypted Data using Dataflow Authentication}, booktitle={Privacy Enhancing Technologies Symposium (PETS/PoPETS)}, author={Fischer, Andreas and Fuhry, Benny and Kerschbaum, Florian and Bodden, Eric}, year={2020} }"},"user_id":"5786","main_file_link":[{"url":"http://www.bodden.de/pubs/ffk+20computation.pdf"}],"_id":"20511","language":[{"iso":"eng"}],"date_updated":"2022-01-06T06:54:29Z","year":"2020","title":"Computation on Encrypted Data using Dataflow Authentication","status":"public","author":[{"first_name":"Andreas","last_name":"Fischer","full_name":"Fischer, Andreas"},{"first_name":"Benny","last_name":"Fuhry","full_name":"Fuhry, Benny"},{"first_name":"Florian","last_name":"Kerschbaum","full_name":"Kerschbaum, Florian"},{"first_name":"Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","full_name":"Bodden, Eric","id":"59256"}]},{"user_id":"5786","language":[{"iso":"eng"}],"_id":"20512","page":"185-198","date_updated":"2022-01-06T06:54:29Z","author":[{"first_name":"Stefan","last_name":"Krüger","full_name":"Krüger, Stefan"},{"full_name":"Ali, Karim","first_name":"Karim","last_name":"Ali"},{"full_name":"Bodden, Eric","first_name":"Eric","last_name":"Bodden"}],"title":"CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs","status":"public","year":"2020","department":[{"_id":"76"}],"type":"conference","date_created":"2020-11-26T08:51:01Z","related_material":{"link":[{"url":"http://www.bodden.de/pubs/krueger20cognicryptgen.pdf","relation":"confirmation"}]},"citation":{"chicago":"Krüger, Stefan, Karim Ali, and Eric Bodden. “CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs.” In <i>International Symposium on Code Generation and Optimization (CGO)</i>, 185–98, 2020.","short":"S. Krüger, K. Ali, E. Bodden, in: International Symposium on Code Generation and Optimization (CGO), 2020, pp. 185–198.","apa":"Krüger, S., Ali, K., &#38; Bodden, E. (2020). CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs. <i>International Symposium on Code Generation and Optimization (CGO)</i>, 185–198.","ieee":"S. Krüger, K. Ali, and E. Bodden, “CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs,” in <i>International Symposium on Code Generation and Optimization (CGO)</i>, 2020, pp. 185–198.","ama":"Krüger S, Ali K, Bodden E. CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs. In: <i>International Symposium on Code Generation and Optimization (CGO)</i>. ; 2020:185-198.","bibtex":"@inproceedings{Krüger_Ali_Bodden_2020, title={CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs}, booktitle={International Symposium on Code Generation and Optimization (CGO)}, author={Krüger, Stefan and Ali, Karim and Bodden, Eric}, year={2020}, pages={185–198} }","mla":"Krüger, Stefan, et al. “CogniCrypt_GEN - Generating Code for the Secure Usage of Crypto APIs.” <i>International Symposium on Code Generation and Optimization (CGO)</i>, 2020, pp. 185–98."},"publication":"International Symposium on Code Generation and Optimization (CGO)"},{"user_id":"5786","main_file_link":[{"url":"https://digital.ub.uni-paderborn.de/hs/document/preview/3500836"}],"_id":"20513","language":[{"iso":"eng"}],"publisher":"Universitaetsbibliothek Paderborn","date_updated":"2022-01-06T06:54:29Z","year":"2020","title":"CogniCrypt -- The Secure Integration of Cryptographic Software","status":"public","author":[{"full_name":"Krüger, Stefan","last_name":"Krüger","first_name":"Stefan"}],"type":"dissertation","department":[{"_id":"76"}],"date_created":"2020-11-26T09:02:19Z","abstract":[{"text":"Frühere Studien haben empirisch offenbart, dass Fehlbenutzungen von kryptographischen APIs in Softwareanwendungen weitverbreitet sind. Dies geschieht vor allem, weil Software-Entwickler_innen aufgrund schlechten API-Designs und fehlenden Kryptographiewissens Probleme bekommen, wenn sie versuchen kryptographische Features zu implementieren. Die Literatur liefert mehrere Ansätze und Vorschläge diese Probleme zu lösen, aber alle scheitern schlussendlich auf die eine oder andere Weise daran die Anforderungen der Entwickler_innenzu erfüllen. Das Resultat ist eine insgesamt lückenhafte Landschaft verschiedener nur wenigkomplementärer Ansätze.In dieser Arbeit adressieren wir das Problem kryptographischer Fehlbenutzungen systematischer durch CogniCrypt. CogniCrypt integriert verschiedene Arten von Tool Supportin einen gemeinsamen Ansatz, der Entwickler_innen davon befreit wissen zu müssen, wie diese APIs benutzt werden müssen. Zentral für unseren Ansatz ist CrySL, eine Beschreibungssprache,die die kognitive Lücke zwischen Kryptographie-Expert_innen und Software-Entwickler_innenüberbrückt. CrySL ermöglicht es Kryptographie-Expert_innen zu spezifizeren, wie die APIs,die sie bereitstellen, richtig benutzt werden. Wir haben einen Compiler für CrySL implementiert, der es erlaubt auf CrySL-Spezifikationen aufbauenden Tool Support zu entwickeln. Wir haben weiterhin die statische Analyse CogniCrypt_SAST und den Code-Generator CogniCrypt_GEN entwickelt. Schlussendlich haben wir CogniCrypt prototypisch implementiert und diesen Prototyp in einem kontrollierten Experiment evaluiert.\r\n","lang":"ger"}],"citation":{"chicago":"Krüger, Stefan. <i>CogniCrypt -- The Secure Integration of Cryptographic Software</i>. Universitaetsbibliothek Paderborn, 2020.","short":"S. Krüger, CogniCrypt -- The Secure Integration of Cryptographic Software, Universitaetsbibliothek Paderborn, 2020.","ieee":"S. Krüger, <i>CogniCrypt -- The Secure Integration of Cryptographic Software</i>. Universitaetsbibliothek Paderborn, 2020.","apa":"Krüger, S. (2020). <i>CogniCrypt -- The Secure Integration of Cryptographic Software</i>. Universitaetsbibliothek Paderborn.","bibtex":"@book{Krüger_2020, title={CogniCrypt -- The Secure Integration of Cryptographic Software}, publisher={Universitaetsbibliothek Paderborn}, author={Krüger, Stefan}, year={2020} }","ama":"Krüger S. <i>CogniCrypt -- The Secure Integration of Cryptographic Software</i>. Universitaetsbibliothek Paderborn; 2020.","mla":"Krüger, Stefan. <i>CogniCrypt -- The Secure Integration of Cryptographic Software</i>. Universitaetsbibliothek Paderborn, 2020."},"supervisor":[{"id":"59256","full_name":"Bodden, Eric","orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden"}]},{"_id":"20518","language":[{"iso":"eng"}],"publisher":"ACM","user_id":"5786","doi":"10.1145/3365438.3410946","author":[{"full_name":"Koch, Thorsten","first_name":"Thorsten","last_name":"Koch","id":"13616"},{"id":"3901","first_name":"Stefan","last_name":"Dziwok","orcid":"http://orcid.org/0000-0002-8679-6673","full_name":"Dziwok, Stefan"},{"id":"3875","first_name":"Jörg","orcid":"0000-0001-6141-4571","last_name":"Holtmann","full_name":"Holtmann, Jörg"},{"full_name":"Bodden, Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","first_name":"Eric","id":"59256"}],"title":"Scenario-based Specification of Security Protocols and Transformation to Security Model Checkers","year":"2020","status":"public","date_updated":"2022-01-06T06:54:29Z","date_created":"2020-11-26T10:19:54Z","department":[{"_id":"76"},{"_id":"241"},{"_id":"662"}],"type":"conference","citation":{"mla":"Koch, Thorsten, et al. “Scenario-Based Specification of Security Protocols and Transformation to Security Model Checkers.” <i>ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)</i>, ACM, 2020, doi:<a href=\"https://doi.org/10.1145/3365438.3410946\">10.1145/3365438.3410946</a>.","bibtex":"@inproceedings{Koch_Dziwok_Holtmann_Bodden_2020, title={Scenario-based Specification of Security Protocols and Transformation to Security Model Checkers}, DOI={<a href=\"https://doi.org/10.1145/3365438.3410946\">10.1145/3365438.3410946</a>}, booktitle={ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)}, publisher={ACM}, author={Koch, Thorsten and Dziwok, Stefan and Holtmann, Jörg and Bodden, Eric}, year={2020} }","ama":"Koch T, Dziwok S, Holtmann J, Bodden E. Scenario-based Specification of Security Protocols and Transformation to Security Model Checkers. In: <i>ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)</i>. ACM; 2020. doi:<a href=\"https://doi.org/10.1145/3365438.3410946\">10.1145/3365438.3410946</a>","ieee":"T. Koch, S. Dziwok, J. Holtmann, and E. Bodden, “Scenario-based Specification of Security Protocols and Transformation to Security Model Checkers,” 2020, doi: <a href=\"https://doi.org/10.1145/3365438.3410946\">10.1145/3365438.3410946</a>.","apa":"Koch, T., Dziwok, S., Holtmann, J., &#38; Bodden, E. (2020). Scenario-based Specification of Security Protocols and Transformation to Security Model Checkers. <i>ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)</i>. <a href=\"https://doi.org/10.1145/3365438.3410946\">https://doi.org/10.1145/3365438.3410946</a>","chicago":"Koch, Thorsten, Stefan Dziwok, Jörg Holtmann, and Eric Bodden. “Scenario-Based Specification of Security Protocols and Transformation to Security Model Checkers.” In <i>ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)</i>. ACM, 2020. <a href=\"https://doi.org/10.1145/3365438.3410946\">https://doi.org/10.1145/3365438.3410946</a>.","short":"T. Koch, S. Dziwok, J. Holtmann, E. Bodden, in: ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20), ACM, 2020."},"publication":"ACM/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems (MODELS ’20)"},{"user_id":"5786","doi":"10.17619/UNIPB/1-1033","publisher":"Paderborn University","_id":"20521","language":[{"iso":"eng"}],"date_updated":"2022-01-06T06:54:29Z","author":[{"full_name":"Gerking, Christopher","last_name":"Gerking","first_name":"Christopher"}],"year":"2020","status":"public","title":"Model-Driven Information Flow Security Engineering for Cyber-Physical Systems","department":[{"_id":"76"}],"type":"dissertation","date_created":"2020-11-26T10:37:17Z","citation":{"apa":"Gerking, C. (2020). <i>Model-Driven Information Flow Security Engineering for Cyber-Physical Systems</i>. Paderborn University. <a href=\"https://doi.org/10.17619/UNIPB/1-1033\">https://doi.org/10.17619/UNIPB/1-1033</a>","ieee":"C. Gerking, <i>Model-Driven Information Flow Security Engineering for Cyber-Physical Systems</i>. Paderborn University, 2020.","short":"C. Gerking, Model-Driven Information Flow Security Engineering for Cyber-Physical Systems, Paderborn University, 2020.","chicago":"Gerking, Christopher. <i>Model-Driven Information Flow Security Engineering for Cyber-Physical Systems</i>. Paderborn University, 2020. <a href=\"https://doi.org/10.17619/UNIPB/1-1033\">https://doi.org/10.17619/UNIPB/1-1033</a>.","mla":"Gerking, Christopher. <i>Model-Driven Information Flow Security Engineering for Cyber-Physical Systems</i>. Paderborn University, 2020, doi:<a href=\"https://doi.org/10.17619/UNIPB/1-1033\">10.17619/UNIPB/1-1033</a>.","ama":"Gerking C. <i>Model-Driven Information Flow Security Engineering for Cyber-Physical Systems</i>. Paderborn University; 2020. doi:<a href=\"https://doi.org/10.17619/UNIPB/1-1033\">10.17619/UNIPB/1-1033</a>","bibtex":"@book{Gerking_2020, title={Model-Driven Information Flow Security Engineering for Cyber-Physical Systems}, DOI={<a href=\"https://doi.org/10.17619/UNIPB/1-1033\">10.17619/UNIPB/1-1033</a>}, publisher={Paderborn University}, author={Gerking, Christopher}, year={2020} }"},"supervisor":[{"full_name":"Bodden, Eric","first_name":"Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","id":"59256"}]},{"language":[{"iso":"eng"}],"_id":"20712","ddc":["000"],"user_id":"477","author":[{"full_name":"Schubert, Philipp","orcid":"0000-0002-8674-1859","last_name":"Schubert","first_name":"Philipp","id":"60543"},{"id":"59256","orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","full_name":"Bodden, Eric"},{"id":"66173","full_name":"Hermann, Ben","orcid":"0000-0001-9848-2017","first_name":"Ben","last_name":"Hermann"}],"title":"Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries","status":"public","year":"2020","has_accepted_license":"1","date_updated":"2022-01-06T06:54:34Z","date_created":"2020-12-14T07:44:11Z","file":[{"creator":"pdschbrt","date_created":"2020-12-14T07:39:07Z","date_updated":"2020-12-14T07:39:07Z","relation":"main_file","file_size":683576,"access_level":"closed","file_name":"main.pdf","content_type":"application/pdf","success":1,"file_id":"20713"}],"department":[{"_id":"76"}],"type":"report","citation":{"chicago":"Schubert, Philipp, Eric Bodden, and Ben Hermann. <i>Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries</i>, 2020.","short":"P. Schubert, E. Bodden, B. Hermann, Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries, 2020.","ieee":"P. Schubert, E. Bodden, and B. Hermann, <i>Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries</i>. 2020.","apa":"Schubert, P., Bodden, E., &#38; Hermann, B. (2020). <i>Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries</i>.","bibtex":"@book{Schubert_Bodden_Hermann_2020, title={Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries}, author={Schubert, Philipp and Bodden, Eric and Hermann, Ben}, year={2020} }","ama":"Schubert P, Bodden E, Hermann B. <i>Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries</i>.; 2020.","mla":"Schubert, Philipp, et al. <i>Accelerating Static Call-Graph, Points-to and Data-Flow Analysis Through Persisted Summaries</i>. 2020."},"file_date_updated":"2020-12-14T07:39:07Z","project":[{"name":"SFB 901","_id":"1"},{"name":"SFB 901 - Project Area B","_id":"3"},{"name":"SFB 901 - Subproject B4","_id":"12"}]},{"department":[{"_id":"76"}],"type":"book_chapter","date_created":"2021-01-11T09:15:41Z","place":"Cham","abstract":[{"text":"Today, software systems are rarely developed monolithically, but may be composed of numerous individually developed features. Their modularization facilitates independent development and verification. While feature-based strategies to verify features in isolation have existed for years, they cannot address interactions between features. The problem with feature interactions is that they are typically unknown and may involve any subset of the features. Contrary, a family-based verification strategy captures feature interactions, but does not scale well when features evolve frequently. To the best of our knowledge, there currently exists no approach with focus on evolving features that combines both strategies and aims at eliminating their respective drawbacks. To fill this gap, we introduce Fefalution, a feature-family-based verification approach based on abstract contracts to verify evolving features and their interactions. Fefalution builds partial proofs for each evolving feature and then reuses the resulting partial proofs in verifying feature interactions, yielding a full verification of the complete software system. Moreover, to investigate whether a combination of both strategies is fruitful, we present the first empirical study for the verification of evolving features implemented by means of feature-oriented programming and by comparing Fefalution with another five family-based approaches varying in a set of optimizations. Our results indicate that partial proofs based on abstract contracts exhibit huge reuse potential, but also come with a substantial overhead for smaller evolution scenarios.\r\n","lang":"eng"}],"citation":{"apa":"Knüppel, A., Krüger, S., Thüm, T., Bubel, R., Krieter, S., Bodden, E., &#38; Schaefer, I. (2020). Using Abstract Contracts for Verifying Evolving Features and Their Interactions. In <i>Lecture Notes in Computer Science</i>. <a href=\"https://doi.org/10.1007/978-3-030-64354-6_5\">https://doi.org/10.1007/978-3-030-64354-6_5</a>","ieee":"A. Knüppel <i>et al.</i>, “Using Abstract Contracts for Verifying Evolving Features and Their Interactions,” in <i>Lecture Notes in Computer Science</i>, Cham, 2020.","short":"A. Knüppel, S. Krüger, T. Thüm, R. Bubel, S. Krieter, E. Bodden, I. Schaefer, in: Lecture Notes in Computer Science, Cham, 2020.","chicago":"Knüppel, Alexander, Stefan Krüger, Thomas Thüm, Richard Bubel, Sebastian Krieter, Eric Bodden, and Ina Schaefer. “Using Abstract Contracts for Verifying Evolving Features and Their Interactions.” In <i>Lecture Notes in Computer Science</i>. Cham, 2020. <a href=\"https://doi.org/10.1007/978-3-030-64354-6_5\">https://doi.org/10.1007/978-3-030-64354-6_5</a>.","mla":"Knüppel, Alexander, et al. “Using Abstract Contracts for Verifying Evolving Features and Their Interactions.” <i>Lecture Notes in Computer Science</i>, 2020, doi:<a href=\"https://doi.org/10.1007/978-3-030-64354-6_5\">10.1007/978-3-030-64354-6_5</a>.","ama":"Knüppel A, Krüger S, Thüm T, et al. Using Abstract Contracts for Verifying Evolving Features and Their Interactions. In: <i>Lecture Notes in Computer Science</i>. ; 2020. doi:<a href=\"https://doi.org/10.1007/978-3-030-64354-6_5\">10.1007/978-3-030-64354-6_5</a>","bibtex":"@inbook{Knüppel_Krüger_Thüm_Bubel_Krieter_Bodden_Schaefer_2020, place={Cham}, title={Using Abstract Contracts for Verifying Evolving Features and Their Interactions}, DOI={<a href=\"https://doi.org/10.1007/978-3-030-64354-6_5\">10.1007/978-3-030-64354-6_5</a>}, booktitle={Lecture Notes in Computer Science}, author={Knüppel, Alexander and Krüger, Stefan and Thüm, Thomas and Bubel, Richard and Krieter, Sebastian and Bodden, Eric and Schaefer, Ina}, year={2020} }"},"publication":"Lecture Notes in Computer Science","user_id":"5786","doi":"10.1007/978-3-030-64354-6_5","language":[{"iso":"eng"}],"_id":"20891","publication_status":"published","date_updated":"2022-01-06T06:54:41Z","publication_identifier":{"issn":["0302-9743","1611-3349"],"isbn":["9783030643539","9783030643546"]},"author":[{"full_name":"Knüppel, Alexander","last_name":"Knüppel","first_name":"Alexander"},{"full_name":"Krüger, Stefan","first_name":"Stefan","last_name":"Krüger"},{"full_name":"Thüm, Thomas","last_name":"Thüm","first_name":"Thomas"},{"full_name":"Bubel, Richard","first_name":"Richard","last_name":"Bubel"},{"full_name":"Krieter, Sebastian","last_name":"Krieter","first_name":"Sebastian"},{"id":"59256","full_name":"Bodden, Eric","first_name":"Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647"},{"full_name":"Schaefer, Ina","last_name":"Schaefer","first_name":"Ina"}],"title":"Using Abstract Contracts for Verifying Evolving Features and Their Interactions","year":"2020","status":"public"},{"_id":"23376","language":[{"iso":"eng"}],"user_id":"5786","doi":"10.1109/ase.2019.00110","author":[{"full_name":"Piskachev, Goran","last_name":"Piskachev","first_name":"Goran"},{"full_name":"Nguyen Quang Do, Lisa","first_name":"Lisa","last_name":"Nguyen Quang Do"},{"full_name":"Johnson, Oshando","last_name":"Johnson","first_name":"Oshando"},{"full_name":"Bodden, Eric","last_name":"Bodden","first_name":"Eric"}],"title":"SWAN_ASSIST: Semi-Automated Detection of Code-Specific, Security-Relevant Methods","status":"public","year":"2020","publication_status":"published","date_updated":"2022-01-06T06:55:50Z","date_created":"2021-08-09T12:03:30Z","department":[{"_id":"241"},{"_id":"662"},{"_id":"76"}],"type":"conference","citation":{"ama":"Piskachev G, Nguyen Quang Do L, Johnson O, Bodden E. SWAN_ASSIST: Semi-Automated Detection of Code-Specific, Security-Relevant Methods. In: <i>2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE)</i>. ; 2020. doi:<a href=\"https://doi.org/10.1109/ase.2019.00110\">10.1109/ase.2019.00110</a>","bibtex":"@inproceedings{Piskachev_Nguyen Quang Do_Johnson_Bodden_2020, title={SWAN_ASSIST: Semi-Automated Detection of Code-Specific, Security-Relevant Methods}, DOI={<a href=\"https://doi.org/10.1109/ase.2019.00110\">10.1109/ase.2019.00110</a>}, booktitle={2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE)}, author={Piskachev, Goran and Nguyen Quang Do, Lisa and Johnson, Oshando and Bodden, Eric}, year={2020} }","mla":"Piskachev, Goran, et al. “SWAN_ASSIST: Semi-Automated Detection of Code-Specific, Security-Relevant Methods.” <i>2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE)</i>, 2020, doi:<a href=\"https://doi.org/10.1109/ase.2019.00110\">10.1109/ase.2019.00110</a>.","short":"G. Piskachev, L. Nguyen Quang Do, O. Johnson, E. Bodden, in: 2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2020.","chicago":"Piskachev, Goran, Lisa Nguyen Quang Do, Oshando Johnson, and Eric Bodden. “SWAN_ASSIST: Semi-Automated Detection of Code-Specific, Security-Relevant Methods.” In <i>2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE)</i>, 2020. <a href=\"https://doi.org/10.1109/ase.2019.00110\">https://doi.org/10.1109/ase.2019.00110</a>.","apa":"Piskachev, G., Nguyen Quang Do, L., Johnson, O., &#38; Bodden, E. (2020). SWAN_ASSIST: Semi-Automated Detection of Code-Specific, Security-Relevant Methods. <i>2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE)</i>. <a href=\"https://doi.org/10.1109/ase.2019.00110\">https://doi.org/10.1109/ase.2019.00110</a>","ieee":"G. Piskachev, L. Nguyen Quang Do, O. Johnson, and E. Bodden, “SWAN_ASSIST: Semi-Automated Detection of Code-Specific, Security-Relevant Methods,” 2020, doi: <a href=\"https://doi.org/10.1109/ase.2019.00110\">10.1109/ase.2019.00110</a>."},"publication":"2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE)"},{"user_id":"5786","doi":"10.1007/978-3-030-54997-8_34","language":[{"iso":"eng"}],"_id":"23377","publication_status":"published","date_updated":"2022-01-06T06:55:50Z","status":"public","year":"2020","title":"AuthCheck: Program-State Analysis for Access-Control Vulnerabilities","author":[{"full_name":"Piskachev, Goran","last_name":"Piskachev","first_name":"Goran"},{"full_name":"Petrasch, Tobias","last_name":"Petrasch","first_name":"Tobias"},{"full_name":"Späth, Johannes","first_name":"Johannes","last_name":"Späth"},{"last_name":"Bodden","first_name":"Eric","full_name":"Bodden, Eric"}],"publication_identifier":{"issn":["0302-9743","1611-3349"]},"type":"book_chapter","department":[{"_id":"241"},{"_id":"662"},{"_id":"76"}],"date_created":"2021-08-09T12:05:09Z","place":"Cham","publication":"Lecture Notes in Computer Science","citation":{"chicago":"Piskachev, Goran, Tobias Petrasch, Johannes Späth, and Eric Bodden. “AuthCheck: Program-State Analysis for Access-Control Vulnerabilities.” In <i>Lecture Notes in Computer Science</i>. Cham, 2020. <a href=\"https://doi.org/10.1007/978-3-030-54997-8_34\">https://doi.org/10.1007/978-3-030-54997-8_34</a>.","short":"G. Piskachev, T. Petrasch, J. Späth, E. Bodden, in: Lecture Notes in Computer Science, Cham, 2020.","apa":"Piskachev, G., Petrasch, T., Späth, J., &#38; Bodden, E. (2020). AuthCheck: Program-State Analysis for Access-Control Vulnerabilities. In <i>Lecture Notes in Computer Science</i>. <a href=\"https://doi.org/10.1007/978-3-030-54997-8_34\">https://doi.org/10.1007/978-3-030-54997-8_34</a>","ieee":"G. Piskachev, T. Petrasch, J. Späth, and E. Bodden, “AuthCheck: Program-State Analysis for Access-Control Vulnerabilities,” in <i>Lecture Notes in Computer Science</i>, Cham, 2020.","ama":"Piskachev G, Petrasch T, Späth J, Bodden E. AuthCheck: Program-State Analysis for Access-Control Vulnerabilities. In: <i>Lecture Notes in Computer Science</i>. ; 2020. doi:<a href=\"https://doi.org/10.1007/978-3-030-54997-8_34\">10.1007/978-3-030-54997-8_34</a>","bibtex":"@inbook{Piskachev_Petrasch_Späth_Bodden_2020, place={Cham}, title={AuthCheck: Program-State Analysis for Access-Control Vulnerabilities}, DOI={<a href=\"https://doi.org/10.1007/978-3-030-54997-8_34\">10.1007/978-3-030-54997-8_34</a>}, booktitle={Lecture Notes in Computer Science}, author={Piskachev, Goran and Petrasch, Tobias and Späth, Johannes and Bodden, Eric}, year={2020} }","mla":"Piskachev, Goran, et al. “AuthCheck: Program-State Analysis for Access-Control Vulnerabilities.” <i>Lecture Notes in Computer Science</i>, 2020, doi:<a href=\"https://doi.org/10.1007/978-3-030-54997-8_34\">10.1007/978-3-030-54997-8_34</a>."}},{"publication":"International Conference for Software Engineering (ICSE)","citation":{"mla":"Benz, Manuel, et al. “Heaps’n Leaks: How Heap Snapshots Improve Android Taint Analysis.” <i>International Conference for Software Engineering (ICSE)</i>, 2020.","bibtex":"@inproceedings{Benz_Krogh Kristensen_Luo_P. Borges Jr._Bodden_Zeller_2020, title={Heaps’n Leaks: How Heap Snapshots Improve Android Taint Analysis}, booktitle={International Conference for Software Engineering (ICSE)}, author={Benz, Manuel and Krogh Kristensen, Erik and Luo, Linghui and P. Borges Jr., Nataniel and Bodden, Eric and Zeller, Andreas}, year={2020} }","ama":"Benz M, Krogh Kristensen E, Luo L, P. Borges Jr. N, Bodden E, Zeller A. Heaps’n Leaks: How Heap Snapshots Improve Android Taint Analysis. In: <i>International Conference for Software Engineering (ICSE)</i>. ; 2020.","ieee":"M. Benz, E. Krogh Kristensen, L. Luo, N. P. Borges Jr., E. Bodden, and A. Zeller, “Heaps’n Leaks: How Heap Snapshots Improve Android Taint Analysis,” 2020.","apa":"Benz, M., Krogh Kristensen, E., Luo, L., P. Borges Jr., N., Bodden, E., &#38; Zeller, A. (2020). Heaps’n Leaks: How Heap Snapshots Improve Android Taint Analysis. <i>International Conference for Software Engineering (ICSE)</i>.","chicago":"Benz, Manuel, Erik Krogh Kristensen, Linghui Luo, Nataniel P. Borges Jr., Eric Bodden, and Andreas Zeller. “Heaps’n Leaks: How Heap Snapshots Improve Android Taint Analysis.” In <i>International Conference for Software Engineering (ICSE)</i>, 2020.","short":"M. Benz, E. Krogh Kristensen, L. Luo, N. P. Borges Jr., E. Bodden, A. Zeller, in: International Conference for Software Engineering (ICSE), 2020."},"type":"conference","department":[{"_id":"76"}],"date_created":"2020-11-26T08:47:56Z","date_updated":"2025-04-07T10:24:14Z","status":"public","year":"2020","title":"Heaps'n Leaks: How Heap Snapshots Improve Android Taint Analysis","author":[{"full_name":"Benz, Manuel","last_name":"Benz","first_name":"Manuel"},{"last_name":"Krogh Kristensen","first_name":"Erik","full_name":"Krogh Kristensen, Erik"},{"first_name":"Linghui","last_name":"Luo","full_name":"Luo, Linghui"},{"full_name":"P. Borges Jr., Nataniel","first_name":"Nataniel","last_name":"P. Borges Jr."},{"full_name":"Bodden, Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647","first_name":"Eric","id":"59256"},{"full_name":"Zeller, Andreas","first_name":"Andreas","last_name":"Zeller"}],"user_id":"15249","language":[{"iso":"eng"}],"_id":"20510"},{"main_file_link":[{"url":"http://www.bodden.de/pubs/tse20ruleGraphs.pdf"}],"language":[{"iso":"eng"}],"_id":"20508","user_id":"15249","status":"public","year":"2020","title":"Explaining Static Analysis with Rule Graphs","author":[{"first_name":"Lisa","last_name":"Nguyen Quang Do","full_name":"Nguyen Quang Do, Lisa"},{"id":"59256","full_name":"Bodden, Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647","first_name":"Eric"}],"date_updated":"2025-04-07T10:22:44Z","date_created":"2020-11-26T08:38:33Z","type":"journal_article","department":[{"_id":"76"}],"publication":"IEEE Transactions on Software Engineering","citation":{"ieee":"L. Nguyen Quang Do and E. Bodden, “Explaining Static Analysis with Rule Graphs,” <i>IEEE Transactions on Software Engineering</i>, 2020.","apa":"Nguyen Quang Do, L., &#38; Bodden, E. (2020). Explaining Static Analysis with Rule Graphs. <i>IEEE Transactions on Software Engineering</i>.","short":"L. Nguyen Quang Do, E. Bodden, IEEE Transactions on Software Engineering (2020).","chicago":"Nguyen Quang Do, Lisa, and Eric Bodden. “Explaining Static Analysis with Rule Graphs.” <i>IEEE Transactions on Software Engineering</i>, 2020.","mla":"Nguyen Quang Do, Lisa, and Eric Bodden. “Explaining Static Analysis with Rule Graphs.” <i>IEEE Transactions on Software Engineering</i>, 2020.","bibtex":"@article{Nguyen Quang Do_Bodden_2020, title={Explaining Static Analysis with Rule Graphs}, journal={IEEE Transactions on Software Engineering}, author={Nguyen Quang Do, Lisa and Bodden, Eric}, year={2020} }","ama":"Nguyen Quang Do L, Bodden E. Explaining Static Analysis with Rule Graphs. <i>IEEE Transactions on Software Engineering</i>. Published online 2020."}},{"date_updated":"2022-01-06T06:54:29Z","title":"A Systematic Analysis and Hardening of the Java Security Architecture","year":"2019","status":"public","author":[{"full_name":"Holzinger, Philipp","first_name":"Philipp","last_name":"Holzinger"}],"user_id":"5786","main_file_link":[{"url":"http://www.bodden.de/pubs/phdHolzinger.pdf"}],"_id":"20522","language":[{"iso":"eng"}],"publisher":"Universität Paderborn","citation":{"ama":"Holzinger P. <i>A Systematic Analysis and Hardening of the Java Security Architecture</i>. Universität Paderborn; 2019.","bibtex":"@book{Holzinger_2019, title={A Systematic Analysis and Hardening of the Java Security Architecture}, publisher={Universität Paderborn}, author={Holzinger, Philipp}, year={2019} }","mla":"Holzinger, Philipp. <i>A Systematic Analysis and Hardening of the Java Security Architecture</i>. Universität Paderborn, 2019.","short":"P. Holzinger, A Systematic Analysis and Hardening of the Java Security Architecture, Universität Paderborn, 2019.","chicago":"Holzinger, Philipp. <i>A Systematic Analysis and Hardening of the Java Security Architecture</i>. Universität Paderborn, 2019.","apa":"Holzinger, P. (2019). <i>A Systematic Analysis and Hardening of the Java Security Architecture</i>. Universität Paderborn.","ieee":"P. Holzinger, <i>A Systematic Analysis and Hardening of the Java Security Architecture</i>. Universität Paderborn, 2019."},"supervisor":[{"full_name":"Bodden, Eric","first_name":"Eric","last_name":"Bodden"}],"type":"dissertation","department":[{"_id":"76"}],"date_created":"2020-11-26T10:44:52Z"},{"type":"dissertation","department":[{"_id":"76"}],"date_created":"2020-11-26T10:47:51Z","citation":{"bibtex":"@book{Nguyen Quang Do_2019, title={User-Centered Tool Design for Data-Flow Analysis}, publisher={Universität Paderborn}, author={Nguyen Quang Do, Lisa}, year={2019} }","ama":"Nguyen Quang Do L. <i>User-Centered Tool Design for Data-Flow Analysis</i>. Universität Paderborn; 2019.","mla":"Nguyen Quang Do, Lisa. <i>User-Centered Tool Design for Data-Flow Analysis</i>. Universität Paderborn, 2019.","short":"L. Nguyen Quang Do, User-Centered Tool Design for Data-Flow Analysis, Universität Paderborn, 2019.","chicago":"Nguyen Quang Do, Lisa. <i>User-Centered Tool Design for Data-Flow Analysis</i>. Universität Paderborn, 2019.","ieee":"L. Nguyen Quang Do, <i>User-Centered Tool Design for Data-Flow Analysis</i>. Universität Paderborn, 2019.","apa":"Nguyen Quang Do, L. (2019). <i>User-Centered Tool Design for Data-Flow Analysis</i>. Universität Paderborn."},"supervisor":[{"id":"59256","orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","full_name":"Bodden, Eric"}],"user_id":"5786","_id":"20524","publisher":"Universität Paderborn","language":[{"iso":"eng"}],"date_updated":"2022-01-06T06:54:29Z","year":"2019","status":"public","title":"User-Centered Tool Design for Data-Flow Analysis","author":[{"first_name":"Lisa","last_name":"Nguyen Quang Do","full_name":"Nguyen Quang Do, Lisa"}]},{"date_updated":"2022-01-06T06:54:29Z","author":[{"id":"48144","full_name":"Stockmann, Lars","first_name":"Lars","last_name":"Stockmann"},{"last_name":"Laux","first_name":"Sven","full_name":"Laux, Sven"},{"full_name":"Bodden, Eric","orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","id":"59256"}],"year":"2019","status":"public","title":"Architectural Runtime Verification","user_id":"5786","doi":"10.1109/ICSA-C.2019.00021","_id":"20525","language":[{"iso":"eng"}],"main_file_link":[{"url":"http://www.bodden.de/pubs/stockmann19architectural.pdf"}],"page":"77-84","citation":{"mla":"Stockmann, Lars, et al. “Architectural Runtime Verification.” <i>2019 IEEE International Conference on Software Architecture Companion (ICSA-C)</i>, 2019, pp. 77–84, doi:<a href=\"https://doi.org/10.1109/ICSA-C.2019.00021\">10.1109/ICSA-C.2019.00021</a>.","apa":"Stockmann, L., Laux, S., &#38; Bodden, E. (2019). Architectural Runtime Verification. <i>2019 IEEE International Conference on Software Architecture Companion (ICSA-C)</i>, 77–84. <a href=\"https://doi.org/10.1109/ICSA-C.2019.00021\">https://doi.org/10.1109/ICSA-C.2019.00021</a>","ieee":"L. Stockmann, S. Laux, and E. Bodden, “Architectural Runtime Verification,” in <i>2019 IEEE International Conference on Software Architecture Companion (ICSA-C)</i>, 2019, pp. 77–84, doi: <a href=\"https://doi.org/10.1109/ICSA-C.2019.00021\">10.1109/ICSA-C.2019.00021</a>.","short":"L. Stockmann, S. Laux, E. Bodden, in: 2019 IEEE International Conference on Software Architecture Companion (ICSA-C), 2019, pp. 77–84.","ama":"Stockmann L, Laux S, Bodden E. Architectural Runtime Verification. In: <i>2019 IEEE International Conference on Software Architecture Companion (ICSA-C)</i>. ; 2019:77-84. doi:<a href=\"https://doi.org/10.1109/ICSA-C.2019.00021\">10.1109/ICSA-C.2019.00021</a>","chicago":"Stockmann, Lars, Sven Laux, and Eric Bodden. “Architectural Runtime Verification.” In <i>2019 IEEE International Conference on Software Architecture Companion (ICSA-C)</i>, 77–84, 2019. <a href=\"https://doi.org/10.1109/ICSA-C.2019.00021\">https://doi.org/10.1109/ICSA-C.2019.00021</a>.","bibtex":"@inproceedings{Stockmann_Laux_Bodden_2019, title={Architectural Runtime Verification}, DOI={<a href=\"https://doi.org/10.1109/ICSA-C.2019.00021\">10.1109/ICSA-C.2019.00021</a>}, booktitle={2019 IEEE International Conference on Software Architecture Companion (ICSA-C)}, author={Stockmann, Lars and Laux, Sven and Bodden, Eric}, year={2019}, pages={77–84} }"},"publication":"2019 IEEE International Conference on Software Architecture Companion (ICSA-C)","department":[{"_id":"76"}],"type":"conference","date_created":"2020-11-27T10:16:59Z"},{"type":"conference","department":[{"_id":"76"}],"date_created":"2020-11-27T10:20:37Z","publication":"2019 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)","citation":{"apa":"Hazhirpasand, M., Ghafari, M., Krüger, S., Bodden, E., &#38; Nierstrasz, O. (2019). The Impact of Developer Experience in Using Java Cryptography. <i>2019 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)</i>, 1–6. <a href=\"https://doi.org/10.1109/ESEM.2019.8870184\">https://doi.org/10.1109/ESEM.2019.8870184</a>","ieee":"M. Hazhirpasand, M. Ghafari, S. Krüger, E. Bodden, and O. Nierstrasz, “The Impact of Developer Experience in Using Java Cryptography,” in <i>2019 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)</i>, 2019, pp. 1–6, doi: <a href=\"https://doi.org/10.1109/ESEM.2019.8870184\">10.1109/ESEM.2019.8870184</a>.","short":"M. Hazhirpasand, M. Ghafari, S. Krüger, E. Bodden, O. Nierstrasz, in: 2019 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), 2019, pp. 1–6.","chicago":"Hazhirpasand, Mohammadreza, Mohammad Ghafari, Stefan Krüger, Eric Bodden, and Oskar Nierstrasz. “The Impact of Developer Experience in Using Java Cryptography.” In <i>2019 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)</i>, 1–6, 2019. <a href=\"https://doi.org/10.1109/ESEM.2019.8870184\">https://doi.org/10.1109/ESEM.2019.8870184</a>.","mla":"Hazhirpasand, Mohammadreza, et al. “The Impact of Developer Experience in Using Java Cryptography.” <i>2019 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)</i>, 2019, pp. 1–6, doi:<a href=\"https://doi.org/10.1109/ESEM.2019.8870184\">10.1109/ESEM.2019.8870184</a>.","ama":"Hazhirpasand M, Ghafari M, Krüger S, Bodden E, Nierstrasz O. The Impact of Developer Experience in Using Java Cryptography. In: <i>2019 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)</i>. ; 2019:1-6. doi:<a href=\"https://doi.org/10.1109/ESEM.2019.8870184\">10.1109/ESEM.2019.8870184</a>","bibtex":"@inproceedings{Hazhirpasand_Ghafari_Krüger_Bodden_Nierstrasz_2019, title={The Impact of Developer Experience in Using Java Cryptography}, DOI={<a href=\"https://doi.org/10.1109/ESEM.2019.8870184\">10.1109/ESEM.2019.8870184</a>}, booktitle={2019 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)}, author={Hazhirpasand, Mohammadreza and Ghafari, Mohammad and Krüger, Stefan and Bodden, Eric and Nierstrasz, Oskar}, year={2019}, pages={1–6} }"},"doi":"10.1109/ESEM.2019.8870184","user_id":"5786","page":"1-6","main_file_link":[{"url":"http://www.bodden.de/pubs/hazhirpasand19impact.pdf"}],"_id":"20527","language":[{"iso":"eng"}],"date_updated":"2022-01-06T06:54:29Z","status":"public","title":"The Impact of Developer Experience in Using Java Cryptography","year":"2019","publication_identifier":{"issn":["1949-3770"]},"author":[{"first_name":"Mohammadreza","last_name":"Hazhirpasand","full_name":"Hazhirpasand, Mohammadreza"},{"full_name":"Ghafari, Mohammad","last_name":"Ghafari","first_name":"Mohammad"},{"last_name":"Krüger","first_name":"Stefan","full_name":"Krüger, Stefan"},{"orcid":"0000-0003-3470-3647","last_name":"Bodden","first_name":"Eric","full_name":"Bodden, Eric","id":"59256"},{"full_name":"Nierstrasz, Oskar","last_name":"Nierstrasz","first_name":"Oskar"}]},{"citation":{"ieee":"G. Piskachev, T. Petrasch, J. Späth, and E. Bodden, “AuthCheck: Program-state Analysis for Access-control Vulnerabilities,” 2019.","apa":"Piskachev, G., Petrasch, T., Späth, J., &#38; Bodden, E. (2019). AuthCheck: Program-state Analysis for Access-control Vulnerabilities. <i>10th Workshop on Tools for Automatic Program Analysis (TAPAS)</i>.","chicago":"Piskachev, Goran, Tobias Petrasch, Johannes Späth, and Eric Bodden. “AuthCheck: Program-State Analysis for Access-Control Vulnerabilities.” In <i>10th Workshop on Tools for Automatic Program Analysis (TAPAS)</i>, 2019.","short":"G. Piskachev, T. Petrasch, J. Späth, E. Bodden, in: 10th Workshop on Tools for Automatic Program Analysis (TAPAS), 2019.","mla":"Piskachev, Goran, et al. “AuthCheck: Program-State Analysis for Access-Control Vulnerabilities.” <i>10th Workshop on Tools for Automatic Program Analysis (TAPAS)</i>, 2019.","bibtex":"@inproceedings{Piskachev_Petrasch_Späth_Bodden_2019, title={AuthCheck: Program-state Analysis for Access-control Vulnerabilities}, booktitle={10th Workshop on Tools for Automatic Program Analysis (TAPAS)}, author={Piskachev, Goran and Petrasch, Tobias and Späth, Johannes and Bodden, Eric}, year={2019} }","ama":"Piskachev G, Petrasch T, Späth J, Bodden E. AuthCheck: Program-state Analysis for Access-control Vulnerabilities. In: <i>10th Workshop on Tools for Automatic Program Analysis (TAPAS)</i>. ; 2019."},"publication":"10th Workshop on Tools for Automatic Program Analysis (TAPAS)","date_created":"2020-11-27T10:21:19Z","department":[{"_id":"76"},{"_id":"241"}],"type":"conference","author":[{"full_name":"Piskachev, Goran","last_name":"Piskachev","first_name":"Goran"},{"full_name":"Petrasch, Tobias","first_name":"Tobias","last_name":"Petrasch"},{"last_name":"Späth","first_name":"Johannes","full_name":"Späth, Johannes"},{"full_name":"Bodden, Eric","first_name":"Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","id":"59256"}],"status":"public","year":"2019","title":"AuthCheck: Program-state Analysis for Access-control Vulnerabilities","date_updated":"2022-01-06T06:54:29Z","_id":"20528","language":[{"iso":"eng"}],"main_file_link":[{"url":"http://www.bodden.de/pubs/piskachev19authcheck.pdf"}],"user_id":"5786"}]
