VLDB 2026 Research / reviewers in the wild / expert
Misha Zitser
dblp:11/4834
· DBLP profile ↗
1ranked-venue papers
1as first author
0since 2021 · last 2004
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% | |
| Network and information security
1 paper |
Systems and software security · 100% |
Topics — the 4 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability discovery |
0.0 | 1 | 2004 | Testing static analysis tools using exploitable buffer overflows from open source code · SIGSOFT FSE 2004 |
Program analysis › static analysis › vulnerability detection
buffer overflow detection |
0.0 | 1 | 2004 | Testing static analysis tools using exploitable buffer overflows from open source code · SIGSOFT FSE 2004 |
Program analysis › static analysis
static analysis tool evaluation |
0.0 | 1 | 2004 | Testing static analysis tools using exploitable buffer overflows from open source code · SIGSOFT FSE 2004 |
Program analysis
static analysis |
0.0 | 1 | 2004 | Testing static analysis tools using exploitable buffer overflows from open source code · SIGSOFT FSE 2004 |
Methods — techniques the papers use, named apart from their topics
static analysis · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2004 | Testing static analysis tools using exploitable buffer overflows from open source codeabstractFive modern static analysis tools (ARCHER, BOON, Poly-Space C Verifier, Splint, and UNO) were evaluated using source code examples containing 14 exploitable buffer overflow vulnerabilities found in various versions of Sendmail, BIND, and WU-FTPD. Each code example included a "BAD" case with and a "OK" case without buffer overflows. Buffer overflows varied and included stack, heap, bss and data buffers; access above and below buffer bounds; access using pointers, indices, and functions; and scope differences between buffer creation and use. Detection rates for the "BAD" examples were low except for Poly-Space and Splint which had average detection rates of 87% and 57%, respectively. However, average false alarm rates were high and roughly 50% for these two tools. On patched programs these two tools produce one warning for every 12 to 46 lines of source code and neither tool appears able to accurately distinguished between vulnerable and patched code. Misha Zitser, Richard Lippmann, Tim Leek |
SIGSOFT FSE | 1 |